What is CVE-2026-70485?
CVE-2026-70485 affects Open WebUI from version 0.9.0 to 0.11.0, where the platform fails to inspect embedded IPv4 addresses within IPv6 addresses during URL validation. This allows attackers to bypass SSRF protections by exploiting the ipaddress.is_global check. Upgrading to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-70485 Open WebUI-nin 0.9.0-dan 0.11.0-a qədər versiyalarına təsir edən boşluqdur. Platforma istifadəçi tərəfindən təqdim edilən URL-lərdəki IPv4 ünvanlarını IPv6 daxilində yoxlamadığına görə, SSRF hücumlarına qarşı müdafiə mexanizmini keçmək mümkün olur. Təhlükəsizlik üçün son versiyaya yeniləmə tövsiyə edilir.
Related CVEs
link basis: same weakness class CWE-918
FAQ1
Which versions of Open WebUI are affected by CVE-2026-70485?
CVE-2026-70485 affects Open WebUI versions 0.9.0 through 0.11.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.