CVE-2026-65105 is a missing-authentication vulnerability in the inference-server setup of NVIDIA NemoClaw for Linux versions 0 through 0.0.25. NemoClaw can configure the local Ollama inference service to listen beyond loopback without authentication. This exposure, combined with insufficient host-origin protections, can allow an attacker to reach Ollama API functionality. DNS rebinding from a malicious website has been reported as a means of accessing the service through a victim browser.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in Nvidia NemoClaw's local AI-agent infrastructure that enables a malicious website to use DNS rebinding to bypass origin checks and reach Ollama's unauthenticated local API. Successful exploitation can give an attacker control of the local model server, enabling model enumeration, public-key theft, model/system-prompt poisoning, insecure-code generation, and conversation-data exfiltration.
A critical NVIDIA NemoClaw configuration flaw that exposes the host's Ollama inference server beyond loopback and disables an important browser-oriented safeguard. Via DNS rebinding, a malicious website can access Ollama's unauthenticated API to manipulate models, including persistently poisoning model templates and thereby influencing OpenClaw AI-agent behavior.
A critical NVIDIA NemoClaw configuration vulnerability in which its Ollama integration binds the local Ollama model server to 0.0.0.0:11434 rather than loopback. Combined with disabled Host-header validation and DNS rebinding, a malicious website can access Ollama's unauthenticated API and persistently poison model templates, potentially hijacking AI-agent behavior.
A high-severity missing-authentication vulnerability (CWE-306) in NVIDIA NemoClaw for Linux inference-server setup. An adjacent-network attacker can access the inference service without authentication, potentially causing information disclosure and denial of service.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.