<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Mein Newsfeed — Open WebUI</title>
<link>https://newsfeed.avintaris.com</link>
<description>News zum Thema Open WebUI</description>
<language>de</language>
<lastBuildDate>Fri, 22 May 2026 21:22:05 +0000</lastBuildDate>
<item>
<title>Open WebUI: Open WebUI — Drei high-severity CVEs in v0.9.5 gepatcht (alle deployed)</title>
<link>https://app.opencve.io/cve/?product=open_webui&amp;vendor=openwebui</link>
<guid isPermaLink="false">https://app.opencve.io/cve/?product=open_webui&amp;vendor=openwebui</guid>
<pubDate>Tue, 19 May 2026 12:00:00 +0000</pubDate>
<category>Open WebUI</category>
<description>OpenCVE publiziert mehrere CVEs alle in v0.9.5 (deployed) gefixt: **CVE-2026-45398 (CVSS 7.5)** Knowledge-Base Access-Control-Lücke. **CVE-2026-45400 (CVSS 8.5)** SSRF via URL-Library-Parsing-Differenzen. **CVE-2026-45401 (CVSS 8.5)** HTTP-Redirect-Validierung umgehbar. Zusätzlich CVE-2026-45315 (CVSS 8.7) in v0.9.3 gefixt, CVE-2026-45672 (CVSS 8.8, code execution bypass) in v0.8.12.</description>
</item>
</channel>
</rss>
