THREAT OPS › Threat News › [GHSA] GHSA-h6x2-583h-x99r (medium) — DNS Rebinding SSRF Bypass
[GHSA] GHSA-h6x2-583h-x99r (medium) — DNS Rebinding SSRF Bypass
GHSA-h6x2-583h-x99r Severity: medium CVE: CVE-2026-54020
DNS Rebinding SSRF Bypass
## Summary Open WebUI vetted user-supplied URLs by resolving the hostname once and rejecting private, loopback and link-local addresses, then let the HTTP client resolve that hostname again at connect time. An attacker who controls the authoritative DNS for a hostname they submit can answer with a public address d
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-54020cve
Original source: https://github.com/advisories/GHSA-h6x2-583h-x99r