IPv6 Vulnerability in Open WebUI Affecting Self-Hosted AI Platform
CVE-2026-70485

7.1HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
4 August 2026

What is CVE-2026-70485?

Open WebUI, a self-hosted AI platform, has a vulnerability that allows verified users to bypass URL validation when the destination is an IPv4 address embedded in a NAT64 prefix. This issue arises because the URL validation mechanism did not check for transition encodings, exposing systems to potential information leakage. This vulnerability affects Open WebUI versions 0.9.0 through 0.11.0 and was addressed in version 0.11.0, enhancing the filtering process for improved security.

Affected Version(s)

open-webui >= 0.9.0, < 0.11.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.