GHSA-34r3-9m95-vq73: Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
HIGHHigh-risk vulnerability — CVSS 7.1
## Summary Open WebUI fetches user-supplied URLs on the server for RAG URL ingestion and web search, and screens the resolved addresses so internal destinations cannot be reached. That screen decided whether a destination was external by asking Python's standard library whether the address is globally routable. Several addresses reserved for internal use answer yes to that question, including 168.63.129.16, the Azure platform channel every Azure virtual machine can reach. …
CVE · detail
- CVE-2026-87999nvd ↗EPSS 0.22%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected