Skip to content
Threat Feed

Tag

Ollama

10 briefs RSS
medium advisory

Unauthenticated External Exposure of Ollama LLM API

Improper configuration of the Ollama LLM server can expose the API to the internet without authentication, enabling remote attackers to conduct model theft, prompt injection, and resource hijacking.

Ollama initial-access llm-security
1r 2t updated
high advisory

Nuxt Ollama API Key Exposure via Public Runtime Configuration

The nuxt-ollama module version 1.2.26 inadvertently publishes Ollama cloud API keys in the client-side serialized runtime configuration, allowing unauthorized remote extraction via standard HTTP requests.

nuxt-ollama credential-exposure nuxt ollama misconfiguration
1t
high advisory

Ollama Model Exfiltration Attempt Detection

This brief describes detection of potential data exfiltration attempts targeting Ollama model metadata and configuration endpoints by adversaries repeatedly querying specific API endpoints to extract sensitive model information.

Ollama model-exfiltration data-leakage
2r 1t
medium advisory

Ollama Abnormal Network Connectivity Detected

This detection identifies unusual network patterns and connection problems within Ollama, encompassing unauthorized API access attempts beyond localhost and warning-level network errors like DNS lookup failures, TCP connection issues, or host resolution problems, which can signal network-based attacks, unauthorized access, or infrastructure reconnaissance.

Ollama network-connectivity anomaly
2r 1t
critical advisory

Ollama Server Possible RCE via Malicious Model Loading

The detection identifies potential remote code execution attempts on Ollama servers through malicious model loading by monitoring error messages and failure patterns during model loading operations, which could indicate malicious model injection, path traversal attempts, or exploitation of model loading mechanisms, leading to arbitrary code execution on the server.

Ollama Server ollama rce model-injection
2r 1t
high advisory

Ollama Resource Exhaustion via Memory Abuse

This brief covers a technique to detect resource exhaustion attacks against Ollama servers by monitoring abnormal memory allocation and runner operations, potentially leading to denial of service or performance degradation.

Ollama resource-exhaustion denial-of-service
2r 1t
high advisory

Ollama API Prompt Injection and Jailbreak Attempts

Detects potential prompt injection and jailbreak attempts against Ollama API endpoints by identifying requests with abnormally long response times, indicative of attackers crafting complex prompts to bypass AI safety controls.

Ollama prompt-injection jailbreak ai-security
1r
medium advisory

Ollama API Endpoint Scan Reconnaissance

Detects potential reconnaissance activity against Ollama servers by identifying sources probing multiple API endpoints within short timeframes, indicative of attackers mapping the API surface for vulnerabilities.

Ollama api-reconnaissance web-application
1r 1t
high advisory

Ollama Abnormal Service Crash Availability Attack

This detection identifies abnormal service crashes, fatal errors, and process terminations in Ollama, potentially indicating exploitation, resource exhaustion, or denial-of-service attacks aimed at disrupting AI model availability and degrading system stability.

Ollama availability denial-of-service crash
2r 1t
high advisory

Ollama API DDoS/Rate Limit Abuse Detection

This detection identifies potential DDoS attacks or rate limit abuse against Ollama API endpoints by detecting excessive request volumes from individual client IP addresses.

Ollama ddos rate-limiting anomaly-detection
2r 1t