{"id":"CVE-2026-88002","title":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tra…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-835"],"vendor":"openwebui","product":"open_webui","affected":["open_webui >= 0.5.0, < 0.11.1"],"patched":["open_webui 0.11.1"],"published":"2026-09-09","updated":"2026-09-14","sourceUpdated":"2026-09-14T19:56:27.077","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88002","references":[{"url":"https://github.com/open-webui/open-webui/commit/5c79ccc9e5c9efc2bc024d8f0b9757652ece929a","label":"security-advisories@github.com"},{"url":"https://github.com/open-webui/open-webui/pull/28034","label":"security-advisories@github.com"},{"url":"https://github.com/open-webui/open-webui/releases/tag/v0.11.1","label":"security-advisories@github.com"},{"url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-jqhh-cjmq-vmv6","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"epss":0.00325,"epssPercentile":0.25702,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T17:12:17.083962Z"},"ingestedAt":"2026-09-13T02:42:38.805Z","slug":"CVE-2026-88002","body":"## Overview\n\nOpen WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tracked visited entries using each message body's optional id field. An authenticated user could store id-less messages in a parent cycle and trigger a non-terminating walk that blocked the async event loop, grew memory until termination, and remained persistent across process restarts. This issue is fixed in version 0.11.1.\n\n## Affected\n\n- `open_webui >= 0.5.0, < 0.11.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `open_webui 0.11.1`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}