CVE-2025-51471: Medium severity Ollama Ollama vulnerability
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51471?
CVE-2025-51471 is classified as a high severity vulnerability due to its potential to allow remote attackers to steal authentication tokens.
How do I fix CVE-2025-51471?
To mitigate CVE-2025-51471, upgrade to a version of Ollama that is beyond 0.9.6, where the vulnerability is addressed.
What is the impact of CVE-2025-51471?
The impact of CVE-2025-51471 includes unauthorized access and potential data breaches stemming from stolen authentication tokens.
What versions of Ollama are affected by CVE-2025-51471?
CVE-2025-51471 affects Ollama versions up to and including 0.6.7.
How does CVE-2025-51471 work?
CVE-2025-51471 exploits a flaw in the server.auth.getAuthorizationToken method where a malicious 'realm' value can lead to token exposure.