THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5x7x-4c3c-qf5w (medium) — Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

[GHSA] GHSA-5x7x-4c3c-qf5w (medium) — Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

medgithub_advisoriesPublished 2026-09-09

GHSA-5x7x-4c3c-qf5w Severity: medium CVE: CVE-2026-88001

Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

## Summary

Open WebUI protects server-side web fetches with two controls: the operator's list of excluded hosts, and a check that refuses private and internal addresses. Neither control was applied to the destination of an HTTP redirect.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5x7x-4c3c-qf5w