CVE-2026-88002
CVE-2026-88002 is a medium-severity vulnerability in Openwebui Open Webui with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-835.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 1% (46th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-835
- Affected product: Openwebui Open Webui
- Published:
- Last modified:
Description
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tracked visited entries using each message body's optional id field. An authenticated user could store id-less messages in a parent cycle and trigger a non-terminating walk that blocked the async event loop, grew memory until termination, and remained persistent across process restarts. This issue is fixed in version 0.11.1.
Frequently asked questions
- What is CVE-2026-88002?
- Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tracked visited entries using each message body's optional id field. An authenticated user could store id-less messages in a parent cycle and trigger a non-terminating walk that blocked the async event loop, grew memory until termination, and remained persistent across process restarts. This issue is fixed in version 0.11.1.
- How severe is CVE-2026-88002?
- CVE-2026-88002 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2026-88002 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (46th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-88002?
- CVE-2026-88002 affects Openwebui Open Webui. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-88002?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-88002 published?
- CVE-2026-88002 was published on 2026-09-09 and last updated on 2026-09-14.
References
- https://github.com/open-webui/open-webui/commit/5c79ccc9e5c9efc2bc024d8f0b9757652ece929a
- https://github.com/open-webui/open-webui/pull/28034
- https://github.com/open-webui/open-webui/releases/tag/v0.11.1
- https://github.com/open-webui/open-webui/security/advisories/GHSA-jqhh-cjmq-vmv6
Affected products (1)
- cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
More vulnerabilities in Openwebui Open Webui
- CVE-2026-44551 — Critical (CVSS 9.1): Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the…
- CVE-2024-8017 — Critical (CVSS 9.0): An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs…
- CVE-2024-7044 — High (CVSS 8.9): A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui…
- CVE-2026-45672 — High (CVSS 8.8): Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the…
- CVE-2024-7043 — High (CVSS 8.8): An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files.…
- CVE-2024-6707 — High (CVSS 8.8): Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path…
All CVEs affecting Openwebui Open Webui →
Other CWE-835 (Loop with Unreachable Exit Condition (Infinite Loop)) vulnerabilities
- CVE-2026-24816 — Critical (CVSS 10.0): Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in datavane tis…
- CVE-2025-21850 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nvmet: Fix crash when a namespace is disabled The…
- CVE-2024-36288 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in…
- CVE-2018-20784 — Critical (CVSS 9.8): In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a…
- CVE-2017-12997 — Critical (CVSS 9.8): The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in…
- CVE-2017-12995 — Critical (CVSS 9.8): The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().
Browse all CWE-835 (Loop with Unreachable Exit Condition (Infinite Loop)) vulnerabilities →