CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-70485

CVE-2026-70485: Server-Side Request Forgery in Open WebUI via NAT64 IP Wrapping Bypass

Alon Barad
Alon Barad
Software Engineer

Aug 4, 2026·5 min read·34 visits

Executive Summary (TL;DR)

An SSRF vulnerability in Open WebUI allows authenticated users to access cloud metadata and internal assets by wrapping private IPv4 addresses in a NAT64 IPv6 prefix.

Open WebUI is susceptible to Server-Side Request Forgery (SSRF) when deployed in networks with NAT64 translation gateways. Authenticated users can bypass host validation checks by encapsulating internal or cloud-metadata IPv4 addresses within globally-routable IPv6 transition prefixes.

Vulnerability Overview

Open WebUI is an extensible, self-hosted AI platform containing features for Retrieval-Augmented Generation (RAG) ingestion, web-search retrieval, and URL-to-markdown conversion. To facilitate these features, the application accepts user-supplied URLs and fetches their content. To prevent Server-Side Request Forgery (SSRF) attacks against internal endpoints, the application implements an IP address validation mechanism.

From version 0.9.0 up to version 0.11.0, this validation mechanism relies on verifying whether the resolved IP addresses of the destination host are globally routable. However, the validation layer is insufficient when deployed within environments utilizing transition mechanisms, such as NAT64 gateways. This insufficient validation allows authenticated remote users to bypass SSRF controls and access local or cloud-metadata endpoints.

Root Cause Analysis

The root cause of the vulnerability lies in the implementation of the IP validation logic in backend/open_webui/retrieval/web/utils.py. The system attempts to resolve user-supplied hostnames and passes the resulting IP addresses to the standard Python ipaddress library to check the is_global property. If the property evaluates to false, the request is blocked as a local or private address.

In dual-stack or IPv6-only network environments, a NAT64 gateway is commonly employed to translate IPv4 traffic to IPv6. This translation is typically accomplished by prepending a Well-Known Prefix (WKP) of 64:ff9b::/96 (RFC 6052) or a Network-Specific Prefix (NSP) to the target IPv4 address. For example, the AWS metadata address 169.254.169.254 becomes [64:ff9b::a9fe:a9fe] under the standard NAT64 prefix.

Python's standard library ipaddress module treats the 64:ff9b::/96 block as part of the globally routable IPv6 address space. Consequently, checking ipaddress.ip_address("64:ff9b::a9fe:a9fe").is_global returns True. This allows transition-wrapped private IPv4 addresses to bypass the validation filters and reach the NAT64 gateway, which decapsulates the address back to its private IPv4 form and completes the connection.

Code Analysis

In vulnerable versions, the application validated the IP address directly using ipaddress.ip_address(ip).is_global without inspecting for transition encodings. The patch introduced in commit 1717b493d83c86afa82aa8bc50139250852dd2f3 implements a helper function _is_global_addr(ip) to recursively unwrap embedded IPv4 addresses from transition protocols.

# File: backend/open_webui/retrieval/web/utils.py
 
def _is_global_addr(ip: str) -> bool:
    addr = ipaddress.ip_address(ip)
    if not addr.is_global:
        return False
    if not isinstance(addr, ipaddress.IPv6Address):
        return True
 
    embedded = []
    if addr.ipv4_mapped:
        embedded.append(addr.ipv4_mapped)
    if addr.sixtofour:
        embedded.append(addr.sixtofour)
    if addr.teredo:
        embedded.extend(addr.teredo)
 
    b = addr.packed
    if b[:12] == b"\x00" * 12:
        embedded.append(ipaddress.IPv4Address(b[12:]))
    elif b[:12] == b"\x00\x64\xff\x9b" + b"\x00" * 8:
        embedded.append(ipaddress.IPv4Address(b[12:]))
    elif b[:6] == b"\x00\x64\xff\x9b\x00\x01":
        if b[8] != 0:
            return False
        embedded.append(ipaddress.IPv4Address(bytes((b[6], b[7], b[9], b[10]))))
 
    return all(ip.is_global for ip in embedded)

The helper parses standard transition mechanisms including IPv4-mapped, 6to4, and Teredo addresses. It also implements manual byte-level matching for the NAT64 Well-Known Prefix (64:ff9b::/96) and the local-translation prefix (64:ff9b:1::/48) to extract the nested IPv4 address. The function then evaluates whether all extracted nested addresses are globally routable.

Exploitation Methodology

An attacker must have authenticated access to the Open WebUI instance. The exploitation relies on entering a specially crafted URL into features like the RAG URL ingestion or web-search field. The attacker translates the target private IPv4 address, such as the link-local metadata address 169.254.169.254, into its hexadecimal representation a9fe:a9fe and prepends the NAT64 prefix.

The resulting URL http://[64:ff9b::a9fe:a9fe]/latest/meta-data/ is submitted to the application. The backend validates the host by resolving the hostname and passing the IPv6 address to ipaddress.is_global. Because the Python library considers this address global, the validation checks pass.

The HTTP request is then dispatched. The outbound packet reaches the NAT64 gateway, which strips the prefix and forwards the TCP connection to the cloud metadata service on 169.254.169.254. The metadata service responds with the requested credentials, which are returned to the application and displayed to the user.

Impact Assessment

Successful exploitation of this SSRF vulnerability permits an authenticated attacker to read sensitive data from internal systems. This is particularly critical in cloud-native environments where the metadata endpoints (such as AWS EC2 metadata, Google Cloud metadata, or Kubernetes APIs) contain active IAM credentials, configuration parameters, and access tokens.

The vulnerability is classified with a CVSS 3.1 score of 7.1 (High) and vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N. The complexity is rated high because the attack succeeds only on environments with dual-stack transitions or active NAT64 configurations. If these conditions are met, the confidentiality impact is high.

While there is currently no evidence of active exploitation in the wild, the maturity of the vulnerability remains theoretical. The exposure is limited to deployments using NAT64 translation services, which are common in IPv6-only container networks.

Remediation & Fix Completeness

The vulnerability is remediated in version 0.11.0 of Open WebUI. Administrators must upgrade their instances to this version or later to apply the validation helper. If an immediate upgrade is not feasible, administrators can disable local web-fetching functionality entirely by configuring the environment variable ENABLE_LOCAL_WEB_FETCH=False.

Additionally, host-level firewall configurations or security groups should be configured to drop outgoing traffic from the Open WebUI container to sensitive private addresses. For example, blocking access to 169.254.169.254/32 at the network level prevents successful exploitation regardless of application-level bypasses.

While the patch effectively blocks transitions using standard prefixes, it does not explicitly handle custom Network-Specific Prefixes (NSPs) defined by local network administrators. If a custom NSP is utilized for the NAT64 gateway, an attacker who obtains the prefix can construct a bypass. Therefore, network-level segregation remains the recommended defense-in-depth practice.

Fix Analysis (1)

Technical Appendix

CVSS Score
7.1/ 10
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N

Affected Systems

Open WebUI Deployments utilizing NAT64 gateways or dual-stack transition networks

Affected Versions Detail

Product
Affected Versions
Fixed Version
open-webui
open-webui
>= 0.9.0, < 0.11.00.11.0
AttributeDetail
CWE IDCWE-918
Attack VectorNetwork (AV:N)
CVSS Score7.1 (High)
Exploit StatusProof-of-Concept / Theoretical Analysis
CISA KEV StatusNot Listed
ImpactInformation Disclosure / Confidentiality Bypass

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1005Data from Local System
Collection
CWE-918
Server-Side Request Forgery (SSRF)

The web application receives a user-supplied URL and fails to properly validate the target destination on networks supporting dual-stack transitions, allowing unauthorized retrieval of internal resources.

Vulnerability Timeline

First remediation commit pushed by vendor
2026-07-27
Official Security Advisory published
2026-08-04
CVE assigned and published
2026-08-04

References & Sources

  • [1]GitHub Advisory (GHSA-8x5v-cpv7-8jjp)
  • [2]Open WebUI Release v0.11.0
  • [3]Backend Validation Fix Commit
  • [4]CVE Official Record Page

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•41 minutes ago•CVE-2026-107725
8.7

CVE-2026-107725: Remote Code Execution via Authorization Bypass in Hazelcast Predicates API

CVE-2026-107725 is a critical security bypass in Hazelcast where missing authorization checks in the MapPermission class permit unprivileged clients to issue queries containing aggregators or projections. This architectural oversight allows attackers to run arbitrary code on the cluster servers under the privileges of the active Hazelcast process.

Amit Schendel
Amit Schendel
1 views•7 min read
•about 2 hours ago•CVE-2026-107396
5.4

CVE-2026-107396: Stored Cross-Site Scripting (XSS) in Indico

A stored Cross-Site Scripting (XSS) vulnerability was identified in Indico, an open-source event management system developed at CERN, prior to version 3.3.13. The vulnerability stems from weak URL validation in custom link fields and lack of HTML sanitization during Marshmallow serialization of event notes. This allows authenticated attackers with event modification privileges to inject malicious payloads that execute in the browser of users viewing the event pages or collaborating on notes.

Alon Barad
Alon Barad
2 views•6 min read
•about 3 hours ago•CVE-2026-107397
4.4

CVE-2026-107397: Stored Cross-Site Scripting via Collaborative Editor Conflict Resolution and Custom Link Fields in Indico

A technical analysis of CVE-2026-107397, a stored Cross-Site Scripting (XSS) vulnerability in Indico's collaborative notes editor and custom link generation fields. Prior to version 3.3.13, Marshmallow serialization schemas omitted HTML sanitization during conflict resolution, and form validators failed to enforce strict URI schemes, enabling authenticated low-privilege attackers to execute arbitrary JavaScript.

Alon Barad
Alon Barad
0 views•7 min read
•about 4 hours ago•CVE-2026-107395
4.3

CVE-2026-107395: Missing Authorization in Indico Legacy Session Export API

An authorization bypass vulnerability exists in the legacy session export API of Indico, an open-source event management system developed at CERN. Due to a missing object-level access check, authenticated users can bypass configuration-level restrictions to extract private session metadata (including session titles, descriptions, and list of conveners) from events that they are otherwise authorized to view.

Alon Barad
Alon Barad
8 views•5 min read
•about 5 hours ago•CVE-2026-107394
6.8

CVE-2026-107394: Server-Side Request Forgery Bypass via Parser Differential in Indico

An incomplete Server-Side Request Forgery (SSRF) validation check in Indico prior to version 3.3.13 allows authenticated event organizers to bypass outbound network restrictions. By utilizing backslash characters within crafted URLs, attackers can exploit a parser differential between the application's validator and the downstream HTTP client library to access internal network resources.

Alon Barad
Alon Barad
7 views•6 min read
•about 6 hours ago•CVE-2026-107717
6.5

CVE-2026-107717: Chat Role Injection and Prompt Boundary Bypass in Banks Library

CVE-2026-107717 represents a critical prompt boundary bypass and chat role injection vulnerability in the Banks Python package (versions prior to 2.5.0). The library parses generated template outputs line-by-line, attempting to validate each segment as a JSON-serialized ChatMessage object without validating the source boundaries of the text. If an application integrates user input directly into a prompt template, a remote, unauthenticated attacker can supply multi-line inputs with structured JSON payloads. This input is then parsed as high-privilege system instructions or tool execution responses, completely hijacking downstream Large Language Model behavior.

Alon Barad
Alon Barad
8 views•6 min read