Server-Side Web Fetch Vulnerability in Open WebUI by Open WebUI
CVE-2026-88001

5MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
9 September 2026

What is CVE-2026-88001?

The Open WebUI, a self-hosted AI platform, exposes a vulnerability where server-side web fetches fail to properly enforce security controls on HTTP redirects. When the AIOHTTP_CLIENT_ALLOW_REDIRECTS setting is enabled, authenticated users can redirect requests to unauthorized hosts, private networks, and cloud metadata services. This can lead to unauthorized access to sensitive data, as content from these sources could be retrieved and processed without sufficient safeguards. The issue has been resolved in version 0.11.1.

Affected Version(s)

open-webui >= 0.9.5, < 0.11.1

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.