CVE-2026-88002
Analyzed Analyzed - Analysis Complete

Denial of Service in Open WebUI via Message Chain

Vulnerability report for CVE-2026-88002, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: GitHub, Inc.

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tracked visited entries using each message body's optional id field. An authenticated user could store id-less messages in a parent cycle and trigger a non-terminating walk that blocked the async event loop, grew memory until termination, and remained persistent across process restarts. This issue is fixed in version 0.11.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openwebui open_webui From 0.5.0 (inc) to 0.11.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Open WebUI versions 0.5.0 to 0.11.0. It involves a flaw in message-chain reconstruction where the system tracks visited messages by their optional ID field but iterates through chat history using map keys. An attacker can create a cycle of messages without IDs, causing the system to enter an infinite loop while processing the chat history. This blocks the async event loop, consumes excessive memory until the process terminates, and persists even after restarting the process.

Detection Guidance

This vulnerability is specific to Open WebUI versions 0.5.0 to 0.11.0 and involves a denial-of-service condition caused by maliciously crafted message chains. Detection requires checking the installed Open WebUI version and monitoring for unusual memory usage or process hangs.

Impact Analysis

If exploited, this vulnerability can cause system slowdowns or complete unresponsiveness due to the blocked event loop and high memory usage. It may lead to denial-of-service conditions, preventing legitimate users from accessing the AI platform. Persistent memory growth could also degrade system performance over time.

Compliance Impact

The vulnerability could lead to denial-of-service (DoS) conditions by consuming excessive system resources, potentially disrupting availability of services. This may impact compliance with GDPR (availability principle) and HIPAA (access control and integrity requirements) if critical systems become unavailable or data integrity is compromised due to resource exhaustion.

Mitigation Strategies

Upgrade Open WebUI to version 0.11.1 or later immediately. If upgrading is not possible, restrict access to authenticated users only and monitor for suspicious message patterns that could trigger the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88002. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart