CVE-2026-87999 | open-webui Open WebUI up to 0.11.0 Address Classification utils.py server-side request forgery
A vulnerability was found in open-webui Open WebUI up to 0.11.0. It has been classified as problematic. The impacted element is an unknown function of the file backend/open_webui/retrieval/web/utils.py of the component Address Classification. The manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-87999. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More