CVE-2026-87011
Analyzed Analyzed - Analysis Complete

Denial of Service in Open WebUI via OAuth Backchannel Logout

Vulnerability report for CVE-2026-87011, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and signing keys before validating a submitted logout token. Each request repeated uncached network fetches, and the signing-key lookup blocked the async event loop, so requests carrying invalid tokens could stall the single-worker instance and amplify traffic to the identity provider when ENABLE_OAUTH_BACKCHANNEL_LOGOUT was enabled. This issue is fixed in version 0.11.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-15
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openwebui open_webui From 0.9.0 (inc) to 0.11.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
CWE-405 The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Open WebUI versions 0.9.0 to 0.11.1 allows unauthenticated attackers to send POST requests to /oauth/backchannel-logout. The handler fetches OIDC discovery documents and signing keys without validating tokens first, causing network delays and blocking the async event loop. Invalid tokens can stall the single-worker instance and increase traffic to the identity provider.

Detection Guidance

Detecting this vulnerability requires checking if your Open WebUI instance is running a vulnerable version (0.9.0 to 0.11.1) and if the OAuth backchannel logout feature is enabled. Inspect the version in your deployment logs or configuration files. Check for stalled requests or unusual traffic patterns to your identity provider when the feature is active.

Impact Analysis

If you run Open WebUI with ENABLE_OAUTH_BACKCHANNEL_LOGOUT enabled, attackers could exploit this to slow down or crash your instance by sending invalid logout tokens. This may lead to service disruptions and increased network costs due to repeated requests to the identity provider.

Compliance Impact

The vulnerability could potentially impact compliance with GDPR and HIPAA by allowing denial-of-service conditions due to unauthenticated requests stalling the system. This may lead to disruptions in service availability, which is a concern under GDPR's requirement for data processing integrity and HIPAA's availability standards.

Mitigation Strategies

Upgrade Open WebUI to version 0.11.1 or later immediately. Disable the ENABLE_OAUTH_BACKCHANNEL_LOGOUT setting if not required. Monitor network traffic for stalled requests or excessive calls to the identity provider during logout operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87011. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart