THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h6x2-583h-x99r (medium) — DNS Rebinding SSRF Bypass

[GHSA] GHSA-h6x2-583h-x99r (medium) — DNS Rebinding SSRF Bypass

medgithub_advisoriesPublished 2026-08-04

GHSA-h6x2-583h-x99r Severity: medium CVE: CVE-2026-54020

DNS Rebinding SSRF Bypass

## Summary Open WebUI vetted user-supplied URLs by resolving the hostname once and rejecting private, loopback and link-local addresses, then let the HTTP client resolve that hostname again at connect time. An attacker who controls the authoritative DNS for a hostname they submit can answer with a public address d

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h6x2-583h-x99r