Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12363 | open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection. |
Mon, 29 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection. | DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. |
Wed, 28 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openwebui
Openwebui open Webui |
|
| CPEs | cpe:2.3:a:openwebui:open_webui:0.5.16:*:*:*:*:*:*:* | |
| Vendors & Products |
Openwebui
Openwebui open Webui |
Mon, 12 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
cvssV3_1
|
Mon, 21 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection. | |
| References |
|
Status: REJECTED
Assigner: mitre
Published:
Updated: 2026-06-29T19:20:59.985Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29446
Updated:
Status : Analyzed
Published: 2025-04-21T17:15:23.883
Modified: 2026-06-17T09:05:22.600
Link: CVE-2025-29446
No data.
OpenCVE Enrichment
No data.
EUVD