PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70485 open-webui CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.610Z and has not been modified since then. Open WebUI versions 0.9.0 through 0.10.0 are vulnerable to internal or cloud-metadata IPv4 address access via NAT64 gateway due to improper URL filtering. This issue allows verified users to wrap internal or cloud-metadata IPv4 addresses in the NAT64 well-known prefix and receive internal response bodies through RAG URL ingestion, URL-to-markdown conversion, or web-search content retrieval. The vulnerability is fixed in version 0.11.0. Organizations using Open WebUI versions 0.9.0 through 0.10.0, especially those with NAT64 gateways configured, should prioritize upgrading to version 0.11.0 to address the vulnerability.

Vendor
open-webui
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-04
Original CVE updated
2026-08-05
Advisory published
2026-08-04
Advisory updated
2026-08-05

Who should care

Organizations using Open WebUI versions 0.9.0 through 0.10.0, especially those with NAT64 gateways configured, should prioritize upgrading to version 0.11.0 to address the vulnerability. Security teams and vulnerability management teams should review and update network configurations for potential exposure and monitor Open WebUI for suspicious activity.

Technical summary

Open WebUI versions 0.9.0 through 0.10.0 are vulnerable to internal or cloud-metadata IPv4 address access via NAT64 gateway due to improper URL filtering. This issue allows verified users to wrap internal or cloud-metadata IPv4 addresses in the NAT64 well-known prefix and receive internal response bodies through RAG URL ingestion, URL-to-markdown conversion, or web-search content retrieval. The vulnerability is fixed in version 0.11.0.

Defensive priority

Organizations using Open WebUI versions 0.9.0 through 0.10.0 should prioritize upgrading to version 0.11.0 to address the vulnerability.

Recommended defensive actions

  • Upgrade Open WebUI to version 0.11.0 or later
  • Review and update network configurations for NAT64 gateways
  • Monitor Open WebUI for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Open WebUI versions 0.9.0 through 0.10.0. Evidence is based on official CVE and NVD sources. The vulnerability allows internal or cloud-metadata IPv4 address access via NAT64 gateway due to improper URL filtering. Defenders should verify affected Open WebUI deployments, especially those with NAT64 gateways configured, and review network configurations for potential exposure.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.610Z and has not been modified since then.