Junglewise Threat Intelligence

CVE-2026-45401: Open WebUI SSRF bypass via HTTP redirect following

CVE-2026-45401 · Severity: high · CVSS 8.5 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI, an interface for large language models, is vulnerable to a security flaw where authenticated users can trick the server into accessing internal network resources. By providing a specially crafted web link that redirects to a private address, an attacker can view sensitive internal data, such as cloud configuration details or local database information. This could lead to the exposure of private infrastructure details and unauthorized access to internal services.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Open WebUI due to improper validation of HTTP redirects. While the 'validate_url()' function checks the initial URL against a blocklist of private and metadata IP addresses, the underlying HTTP clients (requests, aiohttp, and LangChain's WebBaseLoader) follow 3xx redirects by default without re-validating the destination. An authenticated attacker can exploit this by submitting a URL that redirects to internal addresses like 127.0.0.1 or 169.254.169.254. This affects multiple components including web retrieval, image loading, and chat completion middleware. The vulnerability is addressed in version 0.9.5 by disabling automatic redirects or implementing per-hop validation.

Affected products

  • Open WebUI open-webui <= 0.9.4

Timeline

  • 2026-05-10: disclosed
  • 2026-05-14: advisory
  • 2026-05-14: patched: Fixed in version 0.9.5

References

Related threats