CVE-2026-88000
Analyzed Analyzed - Analysis Complete

Infinite Loop in Open WebUI Chat Deletion

Vulnerability report for CVE-2026-88000, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: GitHub, Inc.

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/models/chats.py to follow childrenIds without recording visited message identifiers. An authenticated user could store a cyclic chat tree and delete a message, causing a synchronous infinite loop on the server request loop that blocked every user's requests until the process was killed. This issue is fixed in version 0.11.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openwebui open_webui From 0.10.0 (inc) to 0.11.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Open WebUI, an AI platform. It involves a flaw in the deletion endpoint for chat messages. When a user deletes a message in a cyclic chat tree, it triggers an infinite loop on the server, blocking all user requests until the process is killed.

Detection Guidance

This vulnerability can be detected by checking the Open WebUI version. If your version is between 0.10.0 and 0.11.0, it is vulnerable. Run the command: curl -s http://localhost:8080/api/version | grep version to check the installed version.

Impact Analysis

If exploited, this vulnerability can cause a denial of service for all users of the Open WebUI instance. The server becomes unresponsive due to the infinite loop, preventing anyone from accessing the platform until the process is manually terminated.

Compliance Impact

This vulnerability could lead to denial-of-service conditions, potentially disrupting availability of AI services. For GDPR, this may impact data access rights and service continuity. For HIPAA, it could affect system availability required for protected health information processing.

Mitigation Strategies

Immediately upgrade Open WebUI to version 0.11.1 or later. Stop the vulnerable service and replace it with the patched version to prevent the infinite loop issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88000. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart