Files
open-webui/backend/open_webui
Classic298 d07fd7d6d8 fix: disable redirect following in OAuth picture fetch (SSRF) (#24809)
_process_picture_url validated the initial picture URL with validate_url()
but then aiohttp followed 3xx redirects without re-validating the target,
so a validate_url-passing public URL could 302 to an internal address and
the body was base64-stored in the user's profile_image_url. This is the
sixth call site of the CVE-2026-45401 redirect-bypass cohort; the other
five already pass allow_redirects=AIOHTTP_CLIENT_ALLOW_REDIRECTS. Apply
the same.
2026-05-19 23:57:38 +04:00
..
…
2026-05-19 21:54:38 +04:00
2026-05-13 12:44:12 +09:00
2026-05-12 03:04:35 +09:00
2026-05-09 02:38:08 +09:00
2026-05-19 21:54:38 +04:00
2026-05-14 02:56:44 +09:00
2026-05-19 21:54:38 +04:00