Nankai University team's 362-day Internet-wide scan finds exposed Ollama endpoints grew 53.3% in a year while only 0.43%–2.90% of below-fix IPs upgraded in place
Synopsis
Using XMap to probe port 11434 across the full IPv4 space daily from 2025-02-14 to 2026-02-13 over 362 observed days, a Nankai University team found 152,137 cumulative exposed Ollama endpoints, with daily alive endpoints rising from 10,473 to 16,059 (+53.3%), 26.4% of IPs appearing on a single day, only 0.43%–2.90% of below-fix IPs upgrading in place across five CVE cutoffs, the top five countries/regions holding about 70% of weighted observations, and the top five ASNs all cloud or hosting providers, complemented by PTR and port-443 TLS probing of operational characteristics.
Figure 1: End-to-end measurement and analysis pipeline. The pipeline consists of daily active probing, per-IP enrichment, and longitudinal aggregation stages. Inputs are public IPv4 port 11434 scans; outputs support the analyses in Section 4–7.
· Page 4Interpretation
The first year-scale longitudinal characterization of exposed LLM serving infrastructure: 362 observed days, roughly 4.8 million IP×day observations, and 152,137 cumulative IPs, with daily alive endpoints following a rise-fall-rise pattern from 10,473 to 16,059 (+53.3%) and a cumulative-to-active ratio of 9.47. Prior public analyses of exposed Ollama were largely snapshot-based (for example a one-time Shodan query by Cisco Talos, SentinelOne's analysis of anonymized AI networks, and GreyNoise honeypot observation), which cannot separate transient misconfiguration from persistent deployment; this work extends the window to a full year using first-party daily scanning. Based on daily XMap sweeps of port 11434 across the full IPv4 space; of 365 calendar days, three were lost to collection failures and 11 were low-coverage, leaving 362 observed days, with 99.84% GeoIP and 99.53% ASN match rates.
The exposure surface combines high churn with a long tail: 26.4% of IPs appear on exactly one day, 10.3% appear on 90 or more days, 4.4% (6,619 IPs) appear on 180 or more days, and median IP active days are 5; daily churn averages 775 new and 761 retired IPs, about 5.8% of the mean daily alive population. Moves the question from how many endpoints are exposed to how long they stay exposed and how they turn over, showing that aggregate stability masks substantial population turnover. Based on active-day CDFs and buckets over 152,137 cumulative IPs (P50=5 days, P90=92 days, P99=335 days) plus daily new/retired series after excluding missing and low-coverage days.
The software ecosystem keeps expanding while versions move slowly: daily unique models rose from 1,797 to 5,643 (+214%) and daily unique versions from 112 to 182 (+62.5%); median active days are 5 for IPs, 18 for models, and 114 for versions, and the 2024 release 0.1.33 is the largest single version across the year (287,829 observations, 6.54%). Turns what software is exposed from a static inventory into a three-level lifetime comparison across IPs, models, and versions, showing that platform versions outlive the IPs that carry them. Based on daily /api/tags and /api/version collection (version probing began 2025-02-23, with 87.3%–99.0% parseable coverage) and IP×day-weighted model and version shares.
Remediation is driven mainly by population turnover rather than in-place upgrading: across five CVE cutoffs only 0.43%–2.90% of below-fix IPs upgraded in place, 30%–65% disappeared, and 882–1,796 IPs first appeared after the baseline carrying versions older than the relevant fix; exposure is also concentrated, with the top five countries/regions holding 70.1% of weighted observations, the top five ASNs all cloud or hosting providers, and the top ten re-aggregated providers covering 46.69%. Combines CVE remediation rates with IP-level transition traces to show that an aggregate decline in below-fix share can come from old IPs leaving and new IPs diluting the population rather than from operators patching, and adds a concentration view that localizes leverage to specific (provider, jurisdiction) cells. Based on Sankey transitions and full-year share curves for five selected version cutoffs (<0.1.34, <0.1.47, <0.3.15, <0.6.8, <0.12.4) plus IP×day-weighted Top-k shares and HHI from GeoLite2 (0.1500 country/region, 0.0243 ASN).
Perspective
The work targets public IPv4 addresses reachable on Ollama's default port 11434 from a single measurement vantage point, using the IP address as the unit of observation; it is therefore suited to assessing the scale, lifetime, software composition, and hosting concentration of the public exposure surface, and to informing default changes and tenant notifications by framework developers and cloud or hosting providers. The authors note that the top ten providers cover 46.69% of weighted observations and that cloud and hosting together account for 56.69% of PTR-classifiable IPs, which makes provider-level intervention a practical path; the released aggregate and de-identified data plus the analysis and figure-generation pipeline support future cross-system comparison.
Several scope questions remain for a careful reader: GeoIP/ASN, PTR, and port-443 observations were collected once after the longitudinal window and applied as fixed labels or snapshots, so they cannot reconstruct changes during the year, and GeoIP/ASN mappings may contain residual errors for cloud-hosted IPs; below-fix classification rests on the /api/version string, which the authors explicitly note does not establish exploitability under an endpoint's runtime configuration; and measurement covers only public IPv4 reachable on the default port from a single vantage point, leaving deployments behind NATs, firewalls, or authenticated reverse proxies and those on IPv6 or non-default ports outside the scope. In addition, the five CVE cutoffs were selected from 21 cataloged CVEs under criteria including a visible fix version, a below-fix group covering at least 5% of observations, and coverage of the disclosure timeline and vulnerability types, so remediation dynamics for the remaining CVEs stay an open question.
