top of page
perceptive_background_267k.jpg

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL de…

Published:

3 augustus 2026 om 22:00:00

Alert date:

4 augustus 2026 om 21:03:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Cloud & Virtualization, Emerging Technologies

Open WebUI versions 0.9.0 through 0.11.0 contain a Server-Side Request Forgery (SSRF) vulnerability related to improper IPv6 address validation. The platform's URL filtering mechanism used Python's ipaddress.is_global() to check only the literal IPv6 address without inspecting embedded IPv4 addresses in NAT64 transition encodings. On deployments with a NAT64 gateway, any authenticated user could encode internal or cloud-metadata IPv4 addresses using the NAT64 well-known prefix to bypass the filter. This allowed attackers to access internal network resources or cloud metadata services through RAG URL ingestion, URL-to-markdown conversion, or web-search content retrieval features. The vulnerability poses a significant risk in cloud environments where instance metadata endpoints (e.g., AWS 169.254.169.254) could be accessed. The issue has been patched in Open WebUI version 0.11.0. A fix commit and security advisory have been published on GitHub.

Technical details

Mitigation steps:

Affected products:

Open WebUI 0.9.0
Open WebUI 0.10.x
Open WebUI 0.11.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page