ADVISORY UNAUTH-2026-0001
TYPE exposure-class
PRODUCT Ollama
SEVERITY CRITICAL
Ollama API open to the internet
published 2026-08-05 · updated 2026-08-05
Why it matters
Anyone on the internet can talk to your Ollama server: list your models, run inference on your GPU (you pay the power/hardware bill), and pull or delete models. Exposed Ollama instances are scanned for within hours of going online — this is one of the most commonly found exposed AI services, with well over a hundred thousand of them visible on the public internet.
What a probe sees
GET :11434/api/version answers {"version": ...} and GET /api/tags lists your models — no auth.
Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).
no-auth-by-design
In the wild
HONEYPOT EVIDENCE · only unauth.dev publishes this
SERVICE ollama
PROBES (30d) 367
FIRST SEEN 2026-07-28
LAST SEEN 2026-08-05
Day-granularity probe counts from the unauth.dev botwatch honeypot (367 observed across retained history), refreshed monthly. No source IPs exist in the underlying data. Live view: /botwatch.
Fix it
References
- https://github.com/ollama/ollama/blob/main/docs/faq.md#how-do-i-configure-ollama-server
- https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild
Cite this record
unauth.dev advisory UNAUTH-2026-0001 — observed 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0001. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.