CVE-2026-85180
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Sep 03, 2026
Vendor
unknown
Description
Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause the server to issue GET requests to internal hosts including cloud metadata endpoints.