<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ollama (&lt; 0.1.34) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ollama--0.1.34/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 16:26:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ollama--0.1.34/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution Vulnerability in Ollama</title><link>https://feed.craftedsignal.io/briefs/2026-09-ollama-rce/</link><pubDate>Wed, 30 Sep 2026 16:26:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ollama-rce/</guid><description>A vulnerability in Ollama (CVE-2024-37032) allows a remote, unauthenticated attacker to execute arbitrary code via insufficiently validated API requests.</description><content:encoded><![CDATA[<p>The Ollama service, a popular tool for running large language models, contains a critical vulnerability (CVE-2024-37032) that permits remote, unauthenticated attackers to achieve code execution on the host machine. This flaw arises from improper validation of incoming API requests, allowing an attacker to inject and execute arbitrary payloads. The vulnerability affects versions of Ollama prior to 0.1.34. As Ollama is frequently deployed to host model inference services that may be exposed to internal networks, this poses a significant risk to the underlying host operating system and any sensitive data within the environment. Defenders should prioritize updating instances of Ollama to version 0.1.34 or later to mitigate this risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2024-37032 allows an attacker to gain remote command execution on the host running the Ollama service. This can lead to full system compromise, exfiltration of sensitive data, or lateral movement within the network. Users of Ollama across all supported operating systems, including Linux, Windows, and macOS, are impacted if running vulnerable versions.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all Ollama instances to version 0.1.34 or later to address CVE-2024-37032.</li>
<li>Audit Ollama service network exposure and implement access control lists (ACLs) to restrict access to the API port, typically 11434, to trusted IP addresses only.</li>
<li>Use host-based firewall rules to prevent unauthorized external access to the Ollama API interface.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>vulnerability</category><category>cve-2024-37032</category></item></channel></rss>