RESEARCH
AI Attack Surface Map
As of 2026-02, 12,269 of 175,108 Ollama servers on the public internet are exposed without authentication (~7.0%). On the Attack Surface Map, model endpoints currently lead published classes.
Ranked by published internet-wide zero-auth counts. Honeypot probe volume is attacker interest, not a population estimate. Classes marked collecting have no published population figure yet.
-
Model endpoints
12,269 zero-authInference APIs that answer strangers — list models, chat, pull weights.
-
MCP / tool transport
collectingModel Context Protocol discovery, SSE, and tools catalogs without auth.
-
Agent memory stores
collectingVector / RAG backends that may hold long-lived agent state (OWASP ASI06).
OWASP ASI06
-
Agent runtimes
collectingWorkflow and chatflow builders strangers can invoke or claim as admin.
- n8n —
- Flowise —
- LangServe —
- Dify —
- OpenClaw —
- AutoGen Studio —
- CrewAI Studio —
- Open WebUI —
-
Notebooks & RCE surfaces
collectingInteractive compute that becomes remote code execution when open.
- Jupyter —
-
Prompt & trace backends
collectingObservability that retains prompts, tools, and session state.
- Langfuse —
How to read this
1 class ranked from published census counts; 5 still collecting a population estimate. Snapshot 2026-02-28. Geo probe map (live hits): /map. Per-service census: /census.
Published third-party internet-wide observations, recorded by unauth.dev as a dated census snapshot. Observation windows and scanner methods differ. Services marked collecting have no published population estimate yet — consent-based sample counts from this site are labeled separately and are not population estimates.