Database/AI/ML frameworks & serving
Ollama: DNS rebinding grants a remote page full API access
CVSS 6.6CVE-2024-28224AI/ML frameworks & servingcurated
Impact
DNS rebinding grants a remote page full API access
Who can reach it
Browser of anyone on a network with an Ollama host
What to do
Upgrade past 0.1.29; bind loopback
References
Related entries
- Ollama: Path traversal in the digest fieldCVE-2024-37032 · OllamaHigh
- Ollama: File-existence disclosure via `api/create`CVE-2024-39719 · OllamaHigh
- Ollama: Path traversal in `api/push` discloses server filesystem layoutCVE-2024-39722 · OllamaHigh
- Dagster (gRPC `get_notebook_data`): Local file inclusion — read arbitrary filesCVE-2025-51481 · Dagster (gRPC `get_notebook_data`)Medium
- llama.cpp (GGUF vocabulary parsing, llama_vocab::impl::print_info): MALICIOUS MODEL FILE CRASHES THE SERVER: the GGUFNCVD-2025-020-llama-cpp-gguf-vocabulary-parsin · llama.cpp (GGUF vocabulary parsing, llama_vocab::impl::print_info)Medium
- Kubeflow: SSRFCVE-2023-6570 · KubeflowMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.