AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Ollama: `Client_kwargs` Is Mutated In Place, So URL Credentials Leak Into The Caller'S Dict And Across Model Instances

Constructing ChatOllama, Ollama, or OllamaEmbeddings with a non-empty `client_kwargs` dict mutates that dict and its nested `headers` dict by injecting an `Authorization` header derived from base_url credentials. This leaks credentials into caller-owned objects and causes credentials from one URL to be sent to other hosts when the same dict is reused.

highConfidence 98%LangchainAffected V1.1.0

Origin Analysis

The `_set_clients` validator in chat_models.py, llms.py, and embeddings.py assigns `client_kwargs = self.client_kwargs or {}`, which uses the caller's dict object directly. The `merge_auth_headers` helper then mutates that dict and its nested `headers` dict in place, writing the Authorization header. Because no copy is made, the mutation escapes the model instance.
```python from langchain_ollama import ChatOllama caller_headers = {"X-Tenant": "acme"} shared_kwargs = {"headers": caller_headers} ChatOllama( model="llama3", base_url="https://alice:s3cret@ollama.internal:11434", client_kwargs=shared_kwargs, validate_model_on_init=False, ) print(shared_kwargs) # shows added Authorization print(caller_headers) # shows added Authorization second = ChatOllama( model="llama3", base_url="http://localhost:11434", client_kwargs=shared_kwargs, validate_model_on_init=False, ) print(second._client._client.headers.get("authorization")) # prints Basic ... ```

Fixing Code Block

Edge Case Audit

The shallow copy does not protect against future code that mutates nested structures other than `headers`. If `client_kwargs` contains other nested dicts that are later mutated, the caller may still be affected. Additionally, if any external code relies on the previous in-place mutation behavior, it will break. Rollback: revert these specific changes in the four files. Regression tests covering auth and reuse across instances are recommended.

Ecosystem Topology