CVE-2026-59223: Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Published Jul 9, 2026
·
Updated

Summary

The administrator-configured WEBFETCHFILTERLIST (the allow/block list applied to server-side web fetches: RAG URL ingestion, URL-to-markdown, web-search content fetch) matches hostnames incorrectly, so the filter can be bypassed.

Details

isstringallowed (backend/openwebui/utils/misc.py) matches with str.endswith(...), and the primary web-fetch call site (backend/openwebui/retrieval/web/utils.py) called it with the full URL string, not the hostname:

- Blocklist bypass via path. A blocklist entry !internal.example.com only matches a URL that ends with that string. Any URL with a path (https://internal.example.com/x) ends with /x, so the entry never matches and the fetch proceeds. The blocklist effectively only stopped path-less URLs. - Allowlist false-reject and bypass. An allowlist company.com rejected the legitimate https://api.company.com/status and admitted https://attacker.example/path/company.com. - Non-label-boundary matching at the hostname-shaped call site (retrieval/web/main.py): endswith('corp.com') also matched evilcorp.com, and 10.0.0.1 matched 110.0.0.1.

Impact

An authenticated user able to trigger a server-side web fetch can reach hosts the administrator intended to block with WEBFETCHFILTERLIST.

Open WebUI's primary SSRF protection is a separate, always-on guard that rejects any URL resolving to a non-global IP (validateurl and the connection-layer ssrfsafenewconn, active whenever ENABLERAGLOCALWEBFETCH is off, the default). That guard is unaffected by this issue and continues to block loopback, RFC1918 and link-local addresses, including the 169.254.169.254 cloud-metadata endpoint. This bypass therefore does not grant access to those internal targets. What it defeats is the administrator's ability to block specific publicly-resolvable hosts (internal services reachable from the server over a public IP, e.g. split-horizon DNS or internal PaaS endpoints) and to enforce an allowlist. Fetched content is returned to the requester, so for hosts reachable from the server's network position this is a read/content-disclosure SSRF against the admin-blocked host.

Patch

Matching is now performed on the parsed hostname using DNS label boundaries. A dedicated ishostallowed(host, ...) matches an entry only when host and entry are equal or the entry is a parent domain (host == entry or host.endswith('.' + entry)), so corp.com matches api.corp.com but not evilcorp.com, and IP entries match only the identical address. Both web-fetch call sites pass the parsed hostname rather than the full URL. The generic isstringallowed is retained unchanged for unrelated non-host filters.

Credit

Reported by @addcontent.

Other sources

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, WEBFETCHFILTERLIST matching compared configured host entries against URL strings and non-label-boundary suffixes, allowing path-based blocklist bypasses such as !internal.example.com in a URL path and sibling-domain matches that did not reflect the intended hostname policy. This issue is fixed in version 0.10.0.

MITRE

Affected Software

3 affected componentsFixes available
Open WebUI Open WebUI<0.10.0
openwebui Open WebUI<0.10.0
pip/open-webui<0.10.0
0.10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/open-webui to a version that resolves this vulnerability.

    Fixed in 0.10.0
  2. Upgrade

    Upgrade Open WebUI to a version that resolves this vulnerability.

    Fixed in 0.10.0
  3. Configuration

    Use the parsed hostname for WEB_FETCH_FILTER_LIST matching and enforce DNS label boundary rules so blocklist/allowlist entries apply to exact host or parent domains (label-boundary safe), instead of suffix matching against full URL strings or non-label-boundary endswith/endswith(':port') behavior.

    Open WebUI WEB_FETCH_FILTER_LIST hostname matching = parsed hostname with DNS label boundaries (host == entry OR host.endswith('.' + entry))
  4. Configuration

    Update the web-fetch filtering call sites (e.g., backend/open_webui/retrieval/web/utils.py) to pass the parsed hostname (not the full URL string) into the filter logic.

    Open WebUI (web fetch call site) URL input to WEB_FETCH_FILTER_LIST = hostname only

Event History

Jul 9, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 24, 2026
Advisory Published
via GitHub·08:49 PM
Data Sourced
via GitHub·08:49 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-59223?

The severity of CVE-2026-59223 is rated as medium with a score of 4.3.

2

How do I fix CVE-2026-59223?

To fix CVE-2026-59223, upgrade Open WebUI to version 0.10.0 or later.

3

What type of vulnerability is CVE-2026-59223?

CVE-2026-59223 is a filter bypass vulnerability affecting the host allow/block functionality.

4

What impact does CVE-2026-59223 have on Open WebUI?

CVE-2026-59223 allows unauthorized path-based bypass of configured host blocklists, potentially exposing sensitive resources.

5

Is CVE-2026-59223 easy to exploit?

CVE-2026-59223 has an attack vector classified as network, making it relatively easier to exploit remotely.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-59223 - Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching - SecAlerts