Ollama’s Model Puller Lets Unauthenticated Attackers Snag Cloud Metadata via SSRF
The SSRF bug survives in Ollama 0.33.2 because the tensor model downloader uses a separate HTTP client that skips the redirect guard added for CVE-2026-5530, letting attackers redirect pulls to any reachable address.