Denial of Service Vulnerability in Open WebUI by Open WebUI
CVE-2026-70489

6.5MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
4 August 2026

What is CVE-2026-70489?

Open WebUI versions 0.9.0 to 0.11.0 exhibit a denial of service vulnerability due to flawed automation recurrence parsing. This issue causes significant performance degradation as the backend unnecessarily precomputes an extensive range of future events for minutely and hourly automated rules, leading to system resource exhaustion. As a result, the responsiveness of the entire instance is adversely affected, impacting all users. This vulnerability has been addressed in version 0.11.0, which provides a patch to optimize the scheduling mechanism.

Affected Version(s)

open-webui >= 0.9.0, < 0.11.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.