CVE-2026-85180
Ollama 0.30.0-0.33.2: SSRF when pulling tensor-layer models - blob downloads follow a cross-host redirect unvalidated, so a model reference the operator pulls can steer the server at RFC 1918 addresses and cloud metadata (CVSS 8.7)
- Severity
- high
- Affected product
- Ollama
- Affected versions
- Ollama ≥ 0.30.0, ≤ 0.33.2
- Fixed in
- Ollama not stated by the advisory - upgrade past 0.33.2 (0.33.3 is the next release)
- Added to NewScan
- 2026-09-04
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Ollama from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-04 with the tech_signatures "Ollama" version source. Written as ge/le, NOT lt: the advisory states affected as `0.30.0 through 0.33.2` and names no fixed version, so `le 0.33.2` is the range verbatim while any `lt` would be a guess about which release carries the fix - and a guess that lands high (lt 0.34.0 when 0.33.3 fixed it) is a false positive on every patched install, which is the one error this pack may not make. `ge 0.30.0` is the advisory's own lower bound, not an assumption about older branches. 0.33.3 exists on Docker Hub, so if the fix is confirmed there this row becomes lt 0.33.3 with no widening.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →