CVE-2026-108836 | Ollama up to 0.34.1 Pull API types/model/name.go IsValid server-side request forgery
A vulnerability marked as critical has been reported in Ollama up to 0.34.1. The affected element is the function IsValid of the file types/model/name.go of the component Pull API. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-108836. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More