Server-Side Request Forgery (SSRF) in Open WebUI - #VU146342
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information from internal services.
The vulnerability exists due to server-side request forgery (SSRF) in the server-side URL fetch functionality when processing user-supplied URLs for RAG URL ingestion and web search. A remote user can submit a crafted URL to make the server fetch internal addresses and disclose sensitive information from internal services.
Only the server-side fetch paths are affected, and user interaction is not required. On Azure-hosted deployments, the reachable internal destination includes the Azure platform channel; deployments not hosted on Azure are unaffected for that specific address.