Skip to content
archiveexploit · 10 Sep 2026 · 15:09 UTC

GHSA-34r3-9m95-vq73: Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

EXPLCVE-2026-87999source · GTH
HIGHHigh-risk vulnerability — CVSS 7.1

last 60 dispatches · spectrum

## Summary Open WebUI fetches user-supplied URLs on the server for RAG URL ingestion and web search, and screens the resolved addresses so internal destinations cannot be reached. That screen decided whether a destination was external by asking Python's standard library whether the address is globally routable. Several addresses reserved for internal use answer yes to that question, including 168.63.129.16, the Azure platform channel every Azure virtual machine can reach. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected