CVE-2026-87999

HIGH CVSS 3.1: 7.1 EPSS 0.22%
Updated Sep 10, 2026
Python
Parameter Value
CVSS 7.1 (HIGH)
Fixed In 0.11.1
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Python
Public PoC No

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/utils.py treated Python's globally routable address classification as proof that a destination was external. An authenticated user could make an Azure-hosted instance fetch and return content from 168.63.129.16, the Azure platform channel, as well as other reserved ranges that the standard classification did not reject.

This issue is fixed in version 0.11.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1