MEDIUM 6.3 GitHub

CVE-2026-54020

Open WebUI: DNS Rebinding SSRF Bypass

## Summary Open WebUI vetted user-supplied URLs by resolving the hostname once and rejecting private, loopback and link-local addresses, then let the HTTP client resolve that hostname again at connect time. An attacker who controls the authoritative DNS for a hostname they submit can answer with a public address during the check and an internal one at connect, so the fetch reaches an address the check was meant to block. Every user-reachable fetch gated by that check was affected, and most of th

Affected Products

References

Published: 2026-08-04 · Source: GitHub · Feed updated: 2026-08-04
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-08-04 via GitHub. Affected: pip/open-webui <= 0.10.2.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.