Internet-wide scans have found 175,000 exposed Ollama servers publicly accessible without authentication. Attackers can exploit these to enumerate installed models, submit arbitrary prompts (including prompt injection attempts), abuse GPU compute resources, and trigger long-running inference tasks that degrade performance. Six mitigation strategies are covered: binding Ollama to localhost only, restricting firewall/security group rules, deploying inside private networks, adding an authentication layer via reverse proxy or API gateway, monitoring inference traffic for anomalies, and including Ollama servers in asset inventories. The post concludes with a promotion of Indusface WAS for detecting exposed Ollama instances.
Table of contents
What Attackers Can Do with an Exposed Ollama Server?How to Secure Ollama DeploymentsDetecting Exposed Ollama Servers with Indusface WAS158 Impressions