Open-webui
159 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Open-webui, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Open-webui CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 8 |
| 2025-04 | 0 |
| 2025-05 | 2 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 2 |
| 2025-12 | 3 |
| 2026-01 | 0 |
| 2026-02 | 2 |
| 2026-03 | 4 |
| 2026-04 | 2 |
| 2026-05 | 61 |
| 2026-06 | 17 |
| 2026-07 | 19 |
| 2026-08 | 18 |
| 2026-09 | 18 |
Severity
How the 159 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High68
- Medium78
- Low7
Latest CVEs
The 15 most recently published vulnerabilities affecting Open-webui.
- CVE-2026-88006Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange6.5
- CVE-2026-88005Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange6.5
- CVE-2026-88002Open WebUI: Any authenticated user can hang the server via a cyclic chat message history6.5
- CVE-2026-88001Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets5.0
- CVE-2026-88000Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree6.5
- CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch7.1
- CVE-2026-87998Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion7.1
- CVE-2026-87997Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions4.3
- CVE-2026-87996Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader7.7
- CVE-2026-87995Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin8.7
- CVE-2026-87994Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint4.3
- CVE-2026-87017Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends4.3
- CVE-2026-87016Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite8.1
- CVE-2026-87015Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication6.8
- CVE-2026-87014Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes6.5
Product grouping is registry-driven, with AI assist and human review. How it works