Executive brief
Open WebUI, a user interface for interacting with large language models, is vulnerable to a security flaw that allows attackers to bypass network restrictions. By providing a specially crafted web address, an attacker can force the server to connect to internal systems that are normally protected. This could lead to the exposure of sensitive internal data or unauthorized access to private services within the organization's network.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Open WebUI due to a parsing discrepancy between Python's `urllib.parse.urlparse` and the `requests` library. The `validate_url` function uses `urlparse` to extract and verify the hostname against blocklists or private IP ranges. However, `urlparse` and `requests` interpret backslashes (`\`) differently in the userinfo/host portion of a URL. For example, in a URL like `http://127.0.0.1:6666\@1.1.1.1`, `urlparse` identifies the host as the public IP `1.1.1.1`, while `requests` treats the backslash as a path character and connects to the internal IP `127.0.0.1`. This allows an authenticated attacker to bypass SSRF protections and access internal network resources. The issue is patched in version 0.9.5.
Affected products
- Open WebUI open-webui <= 0.9.4
Timeline
- 2026-05-10: disclosed
- 2026-05-14: advisory
- 2026-05-14: patched