CVE-2026-45338Disclosure(openwebui / open_webui)

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Server-Side Request Forgery (SSRF) vulnerability exists in _process_picture_url() in backend/open_webui/utils/oauth.py (line ~1338). The function fetches arbitrary URLs from OAuth picture claims without applying validate_url(), allowing an attacker to force the server to make HTTP requests to internal resources and exfiltrate the full response. This vulnerability is fixed in 0.9.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_webui

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
open_webui

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-16: 2Technical Details · 2026-05-16: 105-16
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-45338 Server-Side Request Forgery in Open WebUI Before 0.9.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45338 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post announces CVE-2026-45338, a Server‑Side Request Forgery in Open WebUI, and links to vulnerability details and alert subscription, but offers no technical, exploit, or patch information.

    0000067
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45338 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Server-Side Request Forgery (SSRF) vulnerability … https://www.cve.org/CVERecord?id=CVE-2026-45338

    Post summary

    The text announces a newly identified SSRF vulnerability (CVE‑2026‑45338) affecting Open WebUI versions before 0.9.0, providing a link to the CVE record for further details.

    00000176
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenwebuiopen_webui---

Explore more