CVE-2026-88000Medium· 6.5▾ TwilightPoC availableOpen WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/models/chats.py t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
0.3%
Last analysed / modified upstream
0.3% → 0.3%
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/models/chats.py to follow childrenIds without recording visited message identifiers. An authenticated user could store a cyclic chat tree and delete a message, causing a synchronous infinite loop on the server request loop that blocked every user's requests until the process was killed. This issue is fixed in version 0.11.1.
open_webui >= 0.10.0, < 0.11.1Upgrade past the affected range:
open_webui 0.11.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87013Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-88002Medium· 6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87016High· 8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87997Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87011High· 7.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-88001Medium· 5.0Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform