Self-Hosted AI Platform Vulnerability in Open WebUI
CVE-2026-88000
6.5MEDIUM
What is CVE-2026-88000?
The Open WebUI platform has a vulnerability affecting versions 0.10.0 through 0.11.0, allowing authenticated users to exploit the DELETE operation on chat messages. When a user deletes a message using the chat-history deletion helper, the system can enter a synchronous infinite loop, blocking subsequent requests. This results in service disruptions for all users until the process is terminated. The issue has been rectified in version 0.11.1.
Affected Version(s)
open-webui >= 0.10.0, < 0.11.1
