{"id":"CVE-2026-59218","aliases":["GHSA-7rw5-9f7q-xj36"],"title":"Open WebUI: Account enumeration via observable login timing discrepancy","summary":"Open WebUI: Account enumeration via observable login timing discrepancy","severity":"medium","cvss":5.3,"cwe":["CWE-208"],"vendor":"open-webui","product":"open-webui","ecosystem":"pip","affected":["open-webui < 0.10.0"],"patched":["open-webui 0.10.0"],"published":"2026-07-24","updated":"2026-07-24","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-7rw5-9f7q-xj36","references":[{"url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-7rw5-9f7q-xj36"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59218"},{"url":"https://github.com/open-webui/open-webui/pull/26385"},{"url":"https://github.com/open-webui/open-webui/commit/993e74912199c66c522f08ec81abe31d76985e39"},{"url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.0"},{"url":"https://github.com/advisories/GHSA-7rw5-9f7q-xj36"}],"tags":["ghsa","pip"],"epss":0.00413,"epssPercentile":0.35242,"ingestedAt":"2026-07-24T17:34:27.410Z","slug":"CVE-2026-59218","body":"## Overview\n\n### Summary\n\nThe `/api/v1/auths/signin` endpoint leaked whether an email address belonged to a registered account through a response-time side channel. Password verification ran bcrypt only when the email was found in the database; for a non-existent email the request returned early without hashing. The expensive bcrypt comparison therefore made valid-account attempts respond significantly slower (~180 ms) than non-existent ones (~5 ms), so an unauthenticated attacker could enumerate valid accounts by measuring response time.\n\n### Details\n\nOn signin the backend looked the user up by email and only performed the bcrypt password comparison if a record existed. A missing email short-circuited before any hashing, producing the timing gap. The built-in brute-force throttling did not prevent it: sending one request at a time with a small delay between requests stays under the rate limit while still exposing the difference.\n\nObserved in the reporter's run (HTTP 400 for every attempt, the response time is the signal):\n\n```\nEmail                Status   Response time\njoe@example.com      400      186 ms   <- valid account\nlarry@example.com    400        9 ms\njose@example.com     400        6 ms\njames@example.com    400        5 ms\n```\n\n### Impact\n\nAn unauthenticated attacker can enumerate which email addresses are registered accounts, which enables targeted password-spraying against confirmed accounts. The impact is amplified by MFA not being enabled by default. No data is read or modified; the disclosure is limited to account existence.\n\n### Patched\n\nThe authentication path now runs a bcrypt verification against a constant placeholder hash whenever the email does not resolve to an active credential, so a real hash comparison executes on every attempt and the response time is the same whether or not the account exists. Fixed in 0.10.0.\n\n### Credits\n\n@dievus\n\n## Affected packages\n\n- `open-webui < 0.10.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `open-webui 0.10.0`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}