THREAT OPS › Threat News › [GHSA] GHSA-5x7x-4c3c-qf5w (medium) — Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
[GHSA] GHSA-5x7x-4c3c-qf5w (medium) — Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
GHSA-5x7x-4c3c-qf5w Severity: medium CVE: CVE-2026-88001
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
## Summary
Open WebUI protects server-side web fetches with two controls: the operator's list of excluded hosts, and a check that refuses private and internal addresses. Neither control was applied to the destination of an HTTP redirect.
MITRE ATT&CK techniques
- IP AddressesT1590.005
Indicators of compromise
- CVE-2026-88001cve
- 203.0.113.1ipv4
Original source: https://github.com/advisories/GHSA-5x7x-4c3c-qf5w