---
id: CVE-2026-85180
title: >-
  Ollama fails to validate redirect destinations when pulling tensor-layer
  models, allowing unauthenticated attackers to redirect blob downloads to
  arbitrary hosts
summary: >-
  Ollama fails to validate redirect destinations when pulling tensor-layer
  models, allowing unauthenticated attackers to redirect blob downloads to
  arbitrary hosts. An attacker can control a registry, serve a malicious
  tensor-layer manifes…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-918
published: '2026-09-03'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:47:22.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85180'
references:
  - url: 'https://github.com/ollama/ollama'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ollama/ollama/blob/v0.33.2/x/transfer/download.go'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ollama/ollama/issues/17041'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ollama-0.30.0-through-0.33.2-ssrf-via-cross-host-tensor-blob-redirect
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85180.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-85180'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-85180'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00497
epssPercentile: 0.39983
ingestedAt: '2026-09-10T15:53:17.040Z'
vendor: Red Hat
product: ollama
affected:
  - ollama >= 0.30.0 <= 0.33.2
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-03T14:41:25.462957Z'
---

## Overview

Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause the server to issue GET requests to internal hosts including cloud metadata endpoints.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85180.json)
