MEDIUM 6.3 GitHub
CVE-2026-54020
Open WebUI: DNS Rebinding SSRF Bypass
## Summary
Open WebUI vetted user-supplied URLs by resolving the hostname once and rejecting private, loopback and link-local addresses, then let the HTTP client resolve that hostname again at connect time. An attacker who controls the authoritative DNS for a hostname they submit can answer with a public address during the check and an internal one at connect, so the fetch reaches an address the check was meant to block. Every user-reachable fetch gated by that check was affected, and most of th
Affected Products
- pip/open-webui <= 0.10.2
References
- https://github.com/advisories/GHSA-h6x2-583h-x99r
- https://github.com/open-webui/open-webui/security/advisories/GHSA-h6x2-583h-x99r
- https://github.com/open-webui/open-webui/releases/tag/v0.11.0
- https://github.com/advisories/GHSA-h6x2-583h-x99r
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-08-04 via GitHub. Affected: pip/open-webui <= 0.10.2.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.