Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/utils.py treated Python's globally routable address classification as proof that a destination was external. An authenticated user could make an Azure-hosted instance fetch and return content from 168.63.129.16, the Azure platform channel, as well as other reserved ranges that the standard classification did not reject. This issue is fixed in version 0.11.1.
References
| Link | Resource |
|---|---|
| https://github.com/open-webui/open-webui/commit/e3e4bd87df6fc629e7e22081d980d55a7632b8b7 | Patch |
| https://github.com/open-webui/open-webui/pull/27823 | Issue Tracking Patch |
| https://github.com/open-webui/open-webui/releases/tag/v0.11.1 | Release Notes |
| https://github.com/open-webui/open-webui/security/advisories/GHSA-34r3-9m95-vq73 | Exploit Vendor Advisory |
| https://github.com/open-webui/open-webui/security/advisories/GHSA-34r3-9m95-vq73 | Exploit Vendor Advisory |
Configurations
History
16 Sep 2026, 15:13
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/open-webui/open-webui/commit/e3e4bd87df6fc629e7e22081d980d55a7632b8b7 - Patch | |
| References | () https://github.com/open-webui/open-webui/pull/27823 - Issue Tracking, Patch | |
| References | () https://github.com/open-webui/open-webui/releases/tag/v0.11.1 - Release Notes | |
| References | () https://github.com/open-webui/open-webui/security/advisories/GHSA-34r3-9m95-vq73 - Exploit, Vendor Advisory | |
| First Time |
Openwebui
Openwebui open Webui |
|
| CPE | cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:* |
Information
Published : 2026-09-09 22:18
Updated : 2026-09-16 15:13
NVD link : CVE-2026-87999
Mitre link : CVE-2026-87999
CVE.ORG link : CVE-2026-87999
JSON object : View
Products Affected
openwebui
- open_webui
CWE
CWE-918
Server-Side Request Forgery (SSRF)
