


Perceptive Security
SOC/SIEM Consultancy

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL de…
Published:
3 augustus 2026 om 22:00:00
Alert date:
4 augustus 2026 om 21:03:55
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization, Emerging Technologies
Open WebUI versions 0.9.0 through 0.11.0 contain a Server-Side Request Forgery (SSRF) vulnerability related to improper IPv6 address validation. The platform's URL filtering mechanism used Python's ipaddress.is_global() to check only the literal IPv6 address without inspecting embedded IPv4 addresses in NAT64 transition encodings. On deployments with a NAT64 gateway, any authenticated user could encode internal or cloud-metadata IPv4 addresses using the NAT64 well-known prefix to bypass the filter. This allowed attackers to access internal network resources or cloud metadata services through RAG URL ingestion, URL-to-markdown conversion, or web-search content retrieval features. The vulnerability poses a significant risk in cloud environments where instance metadata endpoints (e.g., AWS 169.254.169.254) could be accessed. The issue has been patched in Open WebUI version 0.11.0. A fix commit and security advisory have been published on GitHub.
Technical details
Mitigation steps:
Affected products:
Open WebUI 0.9.0
Open WebUI 0.10.x
Open WebUI 0.11.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-70485
https://github.com/open-webui/open-webui/commit/1717b493d83c86afa82aa8bc50139250852dd2f3
https://github.com/open-webui/open-webui/releases/tag/v0.11.0
https://github.com/open-webui/open-webui/security/advisories/GHSA-8x5v-cpv7-8jjp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
