← Back to search

CVE-2026-70485

7.1 HIGHpublic exploit available

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows users to bypass global routability checks by embedding IPv4 addresses in transition encodings within a NAT64 gateway, potentially exposing internal network responses.
Exploitability
Exploitation requires access to a NAT64 environment and knowledge of the specific encoding techniques. It is moderately difficult due to these preconditions.
Blast radius
If exploited, it could lead to unauthorized access to internal network resources through web interfaces or AI platform integrations.
Prioritized remediation
Update Open WebUI to version 0.11.0 or later to apply proper checks for both IPv4 and IPv6 addresses.
webnetworksecuritybypass

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 address without examining IPv4 addresses embedded in transition encodings. On a deployment with a NAT64 gateway, any verified user could wrap an internal or cloud-metadata IPv4 address in the NAT64 well-known prefix, pass the filter, and receive the internal response body through RAG URL ingestion, URL-to-markdown conversion, or web-search content retrieval. This issue is fixed in 0.11.0.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N

Weaknesses

CWE-918

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.