PT-2026-41195 · Unknown · Open-Webui

Published

2026-05-10

·

Updated

2026-05-16

·

CVE-2026-45400

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.9.5
Description A parsing discrepancy between the urlparse and requests libraries allows for a Server-Side Request Forgery (SSRF) bypass. The validate url() function uses urlparse to verify the hostname; however, urlparse and requests interpret certain URL structures differently. For example, in a URL like http://127.0.0.1:6666@1.1.1.1, urlparse identifies the hostname as 1.1.1.1 (a public address), while requests treats the backslash as a path character and connects to 127.0.0.1 (an internal address), bypassing the validation logic.
Recommendations Update to version 0.9.5.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2026-07439
CVE-2026-45400
GHSA-8W7Q-Q5JP-JVGX

Affected Products

Open-Webui