CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2024-28224: Ollama DNS Rebinding Vulnerability

August 25, 2026

CVE-2024-28224 is a vulnerability in Ollama that allows DNS rebinding attacks to access the Ollama API without authentication. The issue was fixed in Ollama v0.1.29, and NCC Group published the advisory. The recommended fix is to validate the Host header on the server side to allow only authorized values.