← advisory ledger

ADVISORY UNAUTH-2026-0001
TYPE exposure-class
PRODUCT Ollama
SEVERITY CRITICAL

CRITICAL

Ollama API open to the internet

published 2026-08-05 · updated 2026-08-05

Why it matters

Anyone on the internet can talk to your Ollama server: list your models, run inference on your GPU (you pay the power/hardware bill), and pull or delete models. Exposed Ollama instances are scanned for within hours of going online — this is one of the most commonly found exposed AI services, with well over a hundred thousand of them visible on the public internet.

What a probe sees

GET :11434/api/version answers {"version": ...} and GET /api/tags lists your models — no auth.

Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).

no-auth-by-design

In the wild

HONEYPOT EVIDENCE · only unauth.dev publishes this
SERVICE ollama
PROBES (30d) 367
FIRST SEEN 2026-07-28
LAST SEEN 2026-08-05

Day-granularity probe counts from the unauth.dev botwatch honeypot (367 observed across retained history), refreshed monthly. No source IPs exist in the underlying data. Live view: /botwatch.

Fix it

Fix card: ollama-exposed →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0001 — observed 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0001. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.