Exposed Ollama AI servers grow steadily with common security risks
Ollama in the Wild: A Longitudinal Measurement of Exposed Ollama LLM Endpoints at Internet Scale
Networking and Internet Architecture
Summary
Many people are running Ollama large language model servers on the public internet, but we don’t know much about how these setups change over time. The researchers watched these servers for a whole year and found that most are concentrated in a few countries and hosted mostly by cloud providers. They also saw that many servers run old software versions and use common network setups that could lead to security problems. This shows that these exposed AI servers are common, growing, and often not updated, which might pose risks to users and providers.
large language modelOllamainternet endpointsecurity vulnerabilitycloud hostingsoftware updateexposure surfaceIP addressTLS certificatenetwork scanning
Authors
Zuyao Xu, Xiang Li, Yuqi Qiu, Lu Sun
Abstract
Self-hosted large language model (LLM) serving is emerging as a distinct category of Internet service, but we still know little about how these deployments appear and change on the public Internet. We present a 365-day longitudinal measurement of exposed Ollama endpoints (port 11434) from February 2025 to February 2026, combining daily active probing with GeoIP/ASN enrichment, PTR and port-443 host observations, and survival analysis. Across 362 observation days and approximately 4.8 million IP$\times$day observations, 26.4% of the 152,137 cumulative IPs appear for a single day; across five selected CVEs, only 0.43-2.90% of below-fix IPs upgraded in place; the top five countries/regions account for over 70% of weighted observations; and cloud and hosting providers dominate the top ASNs. These results characterize exposed Ollama as a structural exposure surface: persistent, growing, and heavily concentrated. At the same time, old versions, common model choices, cloud and hosting ASNs, PTR categories, and TLS certificate patterns remain visible across the year, indicating recurring insecure deployment practices in cloud infrastructure and the potential reach of provider-level mitigation.