[GH-ISSUE #15841] Subject: Security Report: Unlimited Account Registration & Cloud Resource Abuse #72156

Open
opened 2026-05-05 03:33:56 -05:00 by GiteaMirror · 0 comments
Owner

Originally created by @Nelleron on GitHub (Apr 27, 2026).
Original GitHub issue: https://github.com/ollama/ollama/issues/15841

What is the issue?

Hello Ollama Security Team,

I am writing to report a vulnerability I found in the Ollama Cloud user registration flow that allows for the bypass of usage limits and the creation of unlimited accounts.

Description:
The current registration implementation has weak verification enforcement. While phone number verification is a requirement, it is requested very sporadically during the signup process. This allows an attacker to automate the creation of a large number of accounts without providing valid phone numbers.

Impact:
This vulnerability allows users to abuse Ollama’s cloud resources indefinitely without any usage restrictions. An attacker could cycle through accounts to consume compute resources continuously, bypassing the intended quotas and causing significant financial loss to the company.

I have verified this issue and can provide a video demonstration or steps to reproduce the inconsistent verification behavior.

I am reporting this in good faith and would like to request a Bug Bounty reward for this discovery, given the potential for infrastructure abuse.

Please let me know if you are interested in the full details and how you would like to proceed.

Best regards,
[Nelleron]
You're just ignore me?

чт, 16 апр. 2026 г., 16:51 Владислав Немов vlad.vladisllav@gmail.com:
Показать цитируемый текст

Relevant log output


OS

Windows

GPU

AMD

CPU

AMD

Ollama version

All last versions and this

Originally created by @Nelleron on GitHub (Apr 27, 2026). Original GitHub issue: https://github.com/ollama/ollama/issues/15841 ### What is the issue? Hello Ollama Security Team, I am writing to report a vulnerability I found in the Ollama Cloud user registration flow that allows for the bypass of usage limits and the creation of unlimited accounts. Description: The current registration implementation has weak verification enforcement. While phone number verification is a requirement, it is requested very sporadically during the signup process. This allows an attacker to automate the creation of a large number of accounts without providing valid phone numbers. Impact: This vulnerability allows users to abuse Ollama’s cloud resources indefinitely without any usage restrictions. An attacker could cycle through accounts to consume compute resources continuously, bypassing the intended quotas and causing significant financial loss to the company. I have verified this issue and can provide a video demonstration or steps to reproduce the inconsistent verification behavior. I am reporting this in good faith and would like to request a Bug Bounty reward for this discovery, given the potential for infrastructure abuse. Please let me know if you are interested in the full details and how you would like to proceed. Best regards, [Nelleron] You're just ignore me? чт, 16 апр. 2026 г., 16:51 Владислав Немов <vlad.vladisllav@gmail.com>: Показать цитируемый текст ### Relevant log output ```shell ``` ### OS Windows ### GPU AMD ### CPU AMD ### Ollama version All last versions and this
GiteaMirror added the bug label 2026-05-05 03:33:56 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#72156