CVE-2025-51471
ADVISORY - githubSummary
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint.
EPSS Score: 0.00031 (0.087)
Common Weakness Enumeration (CWE)
ADVISORY - github
Insufficient Verification of Data Authenticity
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in