IPv6 Vulnerability in Open WebUI Affecting Self-Hosted AI Platform
CVE-2026-70485
7.1HIGH
What is CVE-2026-70485?
Open WebUI, a self-hosted AI platform, has a vulnerability that allows verified users to bypass URL validation when the destination is an IPv4 address embedded in a NAT64 prefix. This issue arises because the URL validation mechanism did not check for transition encodings, exposing systems to potential information leakage. This vulnerability affects Open WebUI versions 0.9.0 through 0.11.0 and was addressed in version 0.11.0, enhancing the filtering process for improved security.
Affected Version(s)
open-webui >= 0.9.0, < 0.11.0
