CVE-2026-88001: Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

Published Sep 9, 2026
·
Updated

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEBFETCHFILTERLIST or private-address controls to HTTP redirect destinations when AIOHTTPCLIENTALLOWREDIRECTS was enabled. An authenticated user could redirect the aiohttp and requests fetch paths to excluded hosts, loopback, private networks, or cloud metadata services and route resulting content into web search, URL ingestion, page-fetch tools, or chat image processing. This issue is fixed in version 0.11.1.

Affected Software

1 affected component
Open WebUI Open WebUI>=0.9.5<0.11.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 0.11.1

Event History

Sep 9, 2026
CVE Published
via MITRE·09:38 PM
Data Sourced
via MITRE·09:38 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user can exploit it when server-side web fetching follows redirects. The attacker needs to supply or cause a fetch URL that redirects to an excluded host, loopback address, private network address, or cloud metadata service.

2

Are default filtering controls sufficient to prevent exploitation?

No. In affected versions, WEB_FETCH_FILTER_LIST and private-address controls were not reapplied to redirect destinations when AIOHTTP_CLIENT_ALLOW_REDIRECTS was enabled.

3

Which features may expose fetched internal content?

Redirected content could be routed into web search, URL ingestion, page-fetch tools, or chat image processing. Systems using these server-side fetch paths are relevant to triage.

4

What should be done if upgrading is not immediately possible?

Disable redirect following by setting AIOHTTP_CLIENT_ALLOW_REDIRECTS so redirects are not allowed. This addresses the condition under which redirect destinations bypassed the filtering controls.

5

How can I determine whether my deployment is affected?

Deployments running Open WebUI from 0.9.5 until 0.11.1 are affected if they allow server-side web fetches to follow redirects. Version 0.11.1 fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203