[GH-ISSUE #15840] Security Report: Unlimited Account Registration & Cloud Resource Abuse #72155

Open
opened 2026-05-05 03:33:51 -05:00 by GiteaMirror · 0 comments
Owner

Originally created by @Nelleron on GitHub (Apr 27, 2026).
Original GitHub issue: https://github.com/ollama/ollama/issues/15840

What is the issue?

Hello Ollama Security Team,

I am writing to report a vulnerability I found in the Ollama Cloud user registration flow that allows for the bypass of usage limits and the creation of unlimited accounts.

Description:
The current registration implementation has weak verification enforcement. While phone number verification is a requirement, it is requested very sporadically during the signup process. This allows an attacker to automate the creation of a large number of accounts without providing valid phone numbers.

Impact:
This vulnerability allows users to abuse Ollama’s cloud resources indefinitely without any usage restrictions. An attacker could cycle through accounts to consume compute resources continuously, bypassing the intended quotas and causing significant financial loss to the company.

I have verified this issue and can provide a video demonstration or steps to reproduce the inconsistent verification behavior.

I am reporting this in good faith and would like to request a Bug Bounty reward for this discovery, given the potential for infrastructure abuse.

Please let me know if you are interested in the full details and how you would like to proceed.

Best regards,
[Nelleron]
You're just ignore me?

чт, 16 апр. 2026 г., 16:51 Владислав Немов vlad.vladisllav@gmail.com:
Показать цитируемый текст

Relevant log output


OS

No response

GPU

No response

CPU

No response

Ollama version

No response

Originally created by @Nelleron on GitHub (Apr 27, 2026). Original GitHub issue: https://github.com/ollama/ollama/issues/15840 ### What is the issue? Hello Ollama Security Team, I am writing to report a vulnerability I found in the Ollama Cloud user registration flow that allows for the bypass of usage limits and the creation of unlimited accounts. Description: The current registration implementation has weak verification enforcement. While phone number verification is a requirement, it is requested very sporadically during the signup process. This allows an attacker to automate the creation of a large number of accounts without providing valid phone numbers. Impact: This vulnerability allows users to abuse Ollama’s cloud resources indefinitely without any usage restrictions. An attacker could cycle through accounts to consume compute resources continuously, bypassing the intended quotas and causing significant financial loss to the company. I have verified this issue and can provide a video demonstration or steps to reproduce the inconsistent verification behavior. I am reporting this in good faith and would like to request a Bug Bounty reward for this discovery, given the potential for infrastructure abuse. Please let me know if you are interested in the full details and how you would like to proceed. Best regards, [Nelleron] You're just ignore me? чт, 16 апр. 2026 г., 16:51 Владислав Немов <vlad.vladisllav@gmail.com>: Показать цитируемый текст ### Relevant log output ```shell ``` ### OS _No response_ ### GPU _No response_ ### CPU _No response_ ### Ollama version _No response_
GiteaMirror added the bug label 2026-05-05 03:33:51 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#72155