{"id":"CVE-2026-87011","title":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery doc…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-405","CWE-770"],"vendor":"openwebui","product":"open_webui","affected":["open_webui >= 0.9.0, < 0.11.1"],"patched":["open_webui 0.11.1"],"published":"2026-09-09","updated":"2026-09-15","sourceUpdated":"2026-09-15T16:26:18.880","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-87011","references":[{"url":"https://github.com/open-webui/open-webui/commit/aeda6ff13a25d3b3ba1b303609f35382db22142c","label":"security-advisories@github.com"},{"url":"https://github.com/open-webui/open-webui/releases/tag/v0.11.1","label":"security-advisories@github.com"},{"url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-3g9q-v48f-hh9w","label":"security-advisories@github.com"},{"url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-3g9q-v48f-hh9w","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00358,"epssPercentile":0.29508,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-14T13:41:36.439676Z"},"ingestedAt":"2026-09-14T15:18:19.016Z","slug":"CVE-2026-87011","body":"## Overview\n\nOpen WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and signing keys before validating a submitted logout token. Each request repeated uncached network fetches, and the signing-key lookup blocked the async event loop, so requests carrying invalid tokens could stall the single-worker instance and amplify traffic to the identity provider when ENABLE_OAUTH_BACKCHANNEL_LOGOUT was enabled. This issue is fixed in version 0.11.1.\n\n## Affected\n\n- `open_webui >= 0.9.0, < 0.11.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `open_webui 0.11.1`","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":200088,"id":"CVE-2026-87011","ts":1789395646799,"field":"exploit_available","old":"false","new":"true"}]}