{"type":"bundle","id":"bundle--f297b19d-25ce-534f-9c7a-59ed628dc58b","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--3915ea40-4423-5d4d-8183-94486ffb3fc3","created":"2026-09-20T19:30:53.582Z","modified":"2026-09-20T19:30:53.582Z","name":"Ollama model pulls can SSRF internal hosts via blob redirects","description":"Ollama 0.30.0 through 0.33.2 can follow cross-host tensor blob redirects during model pulls, enabling SSRF into internal hosts. Upgrade past the fixed release.","aliases":["CVE-2026-85180","Ollama tensor blob redirect SSRF"],"first_seen":"2026-09-03T00:00:00.000Z","last_seen":"2026-09-03T12:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"VulnCheck Ollama SSRF advisory","url":"https://www.vulncheck.com/advisories/ollama-0.30.0-through-0.33.2-ssrf-via-cross-host-tensor-blob-redirect"},{"source_name":"NVD CVE-2026-85180","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85180"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-85180-ollama-tensor-blob-redirect-ssrf"}]}]}