THREAT OPS › Threat News › [GHSA] GHSA-34r3-9m95-vq73 (high) — Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
[GHSA] GHSA-34r3-9m95-vq73 (high) — Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
GHSA-34r3-9m95-vq73 Severity: high CVE: CVE-2026-87999
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
## Summary
Open WebUI fetches user-supplied URLs on the server for RAG URL ingestion and web search, and screens the resolved addresses so internal destinations cannot be reached. That screen decided whether a destination was external by asking
Indicators of compromise
- CVE-2026-87999cve
- http://168.63.129.16/?comp=versionsurl
- 168.63.129.16ipv4
Original source: https://github.com/advisories/GHSA-34r3-9m95-vq73