---
id: CVE-2026-59218
aliases:
  - GHSA-7rw5-9f7q-xj36
title: 'Open WebUI: Account enumeration via observable login timing discrepancy'
summary: 'Open WebUI: Account enumeration via observable login timing discrepancy'
severity: medium
cvss: 5.3
cwe:
  - CWE-208
vendor: open-webui
product: open-webui
ecosystem: pip
affected:
  - open-webui < 0.10.0
patched:
  - open-webui 0.10.0
published: '2026-07-24'
updated: '2026-07-24'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-7rw5-9f7q-xj36'
references:
  - url: >-
      https://github.com/open-webui/open-webui/security/advisories/GHSA-7rw5-9f7q-xj36
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59218'
  - url: 'https://github.com/open-webui/open-webui/pull/26385'
  - url: >-
      https://github.com/open-webui/open-webui/commit/993e74912199c66c522f08ec81abe31d76985e39
  - url: 'https://github.com/open-webui/open-webui/releases/tag/v0.10.0'
  - url: 'https://github.com/advisories/GHSA-7rw5-9f7q-xj36'
tags:
  - ghsa
  - pip
epss: 0.00413
epssPercentile: 0.32722
ingestedAt: '2026-07-24T17:34:27.410Z'
---

## Overview

### Summary

The `/api/v1/auths/signin` endpoint leaked whether an email address belonged to a registered account through a response-time side channel. Password verification ran bcrypt only when the email was found in the database; for a non-existent email the request returned early without hashing. The expensive bcrypt comparison therefore made valid-account attempts respond significantly slower (~180 ms) than non-existent ones (~5 ms), so an unauthenticated attacker could enumerate valid accounts by measuring response time.

### Details

On signin the backend looked the user up by email and only performed the bcrypt password comparison if a record existed. A missing email short-circuited before any hashing, producing the timing gap. The built-in brute-force throttling did not prevent it: sending one request at a time with a small delay between requests stays under the rate limit while still exposing the difference.

Observed in the reporter's run (HTTP 400 for every attempt, the response time is the signal):

```
Email                Status   Response time
joe@example.com      400      186 ms   <- valid account
larry@example.com    400        9 ms
jose@example.com     400        6 ms
james@example.com    400        5 ms
```

### Impact

An unauthenticated attacker can enumerate which email addresses are registered accounts, which enables targeted password-spraying against confirmed accounts. The impact is amplified by MFA not being enabled by default. No data is read or modified; the disclosure is limited to account existence.

### Patched

The authentication path now runs a bcrypt verification against a constant placeholder hash whenever the email does not resolve to an active credential, so a real hash comparison executes on every attempt and the response time is the same whether or not the account exists. Fixed in 0.10.0.

### Credits

@dievus

## Affected packages

- `open-webui < 0.10.0`

## Remediation

Upgrade to a patched release:

- `open-webui 0.10.0`
