Open WebUI vulnerabilities allow DoS and message tampering
Three vulnerabilities in Open WebUI allow authenticated users to hang the server via cyclic chat structures and channel members to overwrite other users' messages. Versions 0.5.0-0.11.0 are affected; fixes are available in 0.11.1.
Disclosed 9 September 2026 · Record updated 13 September 2026
Impact
Server denial of service via infinite loops in chat history processing, and message integrity compromise in channels. No data disclosure.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-jqhh-cjmq-vmv6
- github.comhttps://github.com/advisories/GHSA-3cgp-3cqx-j8w2
- github.comhttps://github.com/advisories/GHSA-fmqh-xp37-5hr8
