Skip to content
OllamaGHSA-x9hg-5q6g-q3jr

Ollama vulnerable to Cross-Domain Token Exposure

Medium6.9CVE-2025-51471 · Published Jul 22, 2025 · updated Sep 10, 2026

Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/ollama/ollama
Go
<= 0.9.6No fix yet
Details and references

More Ollama advisories

All Ollama
Advisory
Ollama allows deletion of arbitrary files
Medium6.6Aug 7, 2025
Ollama Server Vulnerable to Denial of Service (DoS) Attack
High7.5May 16, 2025
Ollama Divide By Zero vulnerability
High7.5Mar 20, 2025
Ollama Allocation of Resources Without Limits or Throttling vulnerability
High7.5Mar 20, 2025
Ollama Denial of Service (DoS) via Null Pointer Dereference
High7.5Mar 20, 2025
Ollama Divide by Zero Vulnerability
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.