Files
open-webui/backend/open_webui/utils
Classic298 d07fd7d6d8 fix: disable redirect following in OAuth picture fetch (SSRF) (#24809)
_process_picture_url validated the initial picture URL with validate_url()
but then aiohttp followed 3xx redirects without re-validating the target,
so a validate_url-passing public URL could 302 to an internal address and
the body was base64-stored in the user's profile_image_url. This is the
sixth call site of the CVE-2026-45401 redirect-bypass cohort; the other
five already pass allow_redirects=AIOHTTP_CLIENT_ALLOW_REDIRECTS. Apply
the same.
2026-05-19 23:57:38 +04:00
..
2026-04-19 19:15:05 +09:00
2026-03-17 17:58:01 -05:00
2026-05-19 20:33:46 +04:00
2026-05-19 21:35:04 +04:00
2026-05-19 21:35:04 +04:00
2026-05-19 22:25:39 +04:00
2026-03-17 17:58:01 -05:00
2026-05-11 02:25:11 +09:00