Server-Side Request Forgery (SSRF) in Open WebUI - CVE-2026-34225

 

Server-Side Request Forgery (SSRF) in Open WebUI - CVE-2026-34225

Published: April 24, 2026


Vulnerability identifier: #VU127479
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34225
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose limited sensitive information.

The vulnerability exists due to server-side request forgery in the image edit functionality when processing a user-supplied image URL. A remote user can send a specially crafted request containing a URL to disclose limited sensitive information.

The issue is blind, so the response body cannot be read directly, but response differentials can be used to scan for open ports on the local network.


Affected software

Open WebUI

How to mitigate CVE-2026-34225

Install security update from vendor's website.

Open WebUI - update to 0.8.0

External References

Related Security Bulletins