SSRF Bypass in Open WebUI AI Platform by Open WebUI
CVE-2026-45400
8.5HIGH
What is CVE-2026-45400?
Open WebUI, a self-hosted AI platform, contains a vulnerability due to a parsing inconsistency between the urlparse and requests libraries. This SSRF bypass issue can potentially allow attackers to perform unauthorized server-side requests. The flaw has been addressed in version 0.9.5 of the software, ensuring enhanced security for users operating in offline environments.
Affected Version(s)
open-webui < 0.9.5
