From 66126f38617b9ed00e63f8195565fd174dcc53f5 Mon Sep 17 00:00:00 2001 From: G30 <50341825+silentoplayz@users.noreply.github.com> Date: Thu, 28 May 2026 17:41:56 -0400 Subject: [PATCH] fix(auth): use request.scope["path"] to prevent CVE-2026-48710 (BadHost) (#25123) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Starlette reconstructs request.url.path from the HTTP Host header without validation. An attacker can inject a path into the Host header to make request.url.path return a different value than the path Starlette routes on. The API key endpoint restriction check was using request.url.path to decide whether to allow or deny access — making it bypassable via a crafted Host header on any Starlette version prior to 1.0.1. Fix: replace request.url.path with request.scope["path"], which reads the raw ASGI scope path that Starlette uses for routing. This value is set by the ASGI server from the actual request path and cannot be injected via HTTP headers, making it safe regardless of Starlette version. Affected code path: get_current_user_by_api_key() in backend/open_webui/utils/auth.py (only triggered when ENABLE_API_KEYS_ENDPOINT_RESTRICTIONS is enabled) References: CVE-2026-48710 / BadHost https://arstechnica.com/information-technology/2026/05/millions-of-ai-agents-imperiled-by-critical-vulnerability-in-open-source-package/ --- backend/open_webui/utils/auth.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/backend/open_webui/utils/auth.py b/backend/open_webui/utils/auth.py index 136d216362..1082088b57 100644 --- a/backend/open_webui/utils/auth.py +++ b/backend/open_webui/utils/auth.py @@ -426,7 +426,7 @@ async def get_current_user_by_api_key(request, api_key: str): allowed_paths = [ path.strip() for path in str(request.app.state.config.API_KEYS_ALLOWED_ENDPOINTS).split(',') if path.strip() ] - request_path = request.url.path + request_path = request.scope["path"] # Use raw ASGI path — not spoofable via Host header (CVE-2026-48710) is_allowed = any(request_path == allowed or request_path.startswith(allowed + '/') for allowed in allowed_paths) if not is_allowed: raise HTTPException(