THREAT OPS › Threat News › [NVD] CVE-2026-70485 (HIGH 7.1) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 address without examining IPv4 addre
[NVD] CVE-2026-70485 (HIGH 7.1) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 address without examining IPv4 addre
CVE-2026-70485 CVSS: 7.1 HIGH Published: 2026-08-04T20:16:55.610
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 address without examining IPv4 addresses embedded in transition encodings. On a deployment
Indicators of compromise
- CVE-2026-70485cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70485