Server-Side Request Forgery (SSRF) in Open WebUI - CVE-2026-45347

 

Server-Side Request Forgery (SSRF) in Open WebUI - CVE-2026-45347

Published: May 11, 2026


Vulnerability identifier: #VU130946
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45347
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to trigger arbitrary server-side GET requests.

The vulnerability exists due to server-side request forgery in the PDF generate function when processing user-supplied HTML during PDF export. A remote user can inject a crafted image tag to trigger arbitrary server-side GET requests.

The issue is blind, so responses could not be read during testing, but internal assets may be enumerated through response delays.


Affected software

Open WebUI

How to mitigate CVE-2026-45347

Install security update from vendor's website.

Open WebUI - update to 0.5.11

External References

Related Security Bulletins