SSRF Bypass in Open WebUI AI Platform by Open WebUI
CVE-2026-45400

8.5HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45400?

Open WebUI, a self-hosted AI platform, contains a vulnerability due to a parsing inconsistency between the urlparse and requests libraries. This SSRF bypass issue can potentially allow attackers to perform unauthorized server-side requests. The flaw has been addressed in version 0.9.5 of the software, ensuring enhanced security for users operating in offline environments.

Affected Version(s)

open-webui < 0.9.5

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.