CVE-2026-34225General(openwebui / open_webui)

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and below contain a Blind Server Side Request Forgery in the functionality that allows editing an image via a prompt. The affected function performs a GET request to a user-provided URL with no restriction on the domain, allowing the local address space to be accessed. Since the SSRF is blind (the response cannot be read), the primary impact is port scanning of the local network, as whether a port is open can be determined based on whether the GET request succeeds or fails. These response differentials can be automated to iterate through the entire port range and identify open ports. If the service running on an open port can be inferred, an attacker may be able to interact with it in a meaningful way, provided the service offers state-changing GET request endpoints. This issue was unresolved at the time of publication.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_webui

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
open_webui

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-14: 3Technical Details · 2026-04-14: 204-14
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-34225 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and below contain a Blind Server Side Request Forger… https://www.cve.org/CVERecord?id=CVE-2026-34225

    Post summary

    The post references CVE-2026-34225, noting a blind SSRF flaw in Open WebUI 0.7.2 and earlier, but offers no PoC, exploit, or patch information.

    0100066
    57.2K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-34225 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34225 #CVE-2026-34225 #CVE #Medium #CyberSecurity #InfoSec https://t.co/IqzgmM5R9j

    Post summary

    The tweet announces CVE‑2026‑34225 with basic severity information but provides no deeper technical, exploit, or mitigation details.

    0000033
    137 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34225 Blind Server Side Request Forgery in Open WebUI 0.7.2 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34225

    Post summary

    A blind SSRF vulnerability (CVE-2026-34225) affecting Open WebUI versions 0.7.2 and earlier has been reported, but no PoC, exploit, active exploitation, or patch details are provided.

    0000045
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenwebuiopen_webui---

Explore more