PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70489 open-webui CVE debrief

Open WebUI, a self-hosted AI platform, had a vulnerability in versions 0.9.0 to 0.10.0 where automation recurrence parsing could cause significant availability impact. The issue, fixed in version 0.11.0, involved inefficient computation of recurring events that could block the event loop used for scheduler, HTTP, and WebSocket traffic. This could lead to performance degradation and potential downtime for users of the instance. Defenders should be aware of the potential impact and take steps to verify and mitigate the vulnerability.

Vendor
open-webui
Product
Unknown
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-04
Original CVE updated
2026-09-18
Advisory published
2026-08-04
Advisory updated
2026-09-18

Who should care

Defenders managing Open WebUI instances should verify their version and upgrade to 0.11.0 if necessary to prevent potential availability impact. This includes operators, platform administrators, and security teams responsible for maintaining the instance. They should be aware of the potential impact and take steps to verify and mitigate the vulnerability.

Why it matters

Defenders managing Open WebUI instances should verify their version and upgrade to 0.11.0 if necessary to prevent potential availability impact due to inefficient automation recurrence parsing.

  • Potential availability impact for users of the instance
  • Inefficient computation of recurring events could block the event loop
  • Verification of Open WebUI version and upgrade to 0.11.0 is necessary

Technical summary

The vulnerability in Open WebUI versions 0.9.0 to 0.10.0 causes availability impact due to inefficient automation recurrence parsing. The issue is fixed in version 0.11.0, which improves the computation of recurring events and prevents the event loop from being blocked. This fix should prevent potential downtime and performance degradation for users of the instance. The vulnerability is caused by the inefficient computation of recurring events, which can block the event loop used for scheduler, HTTP, and WebSocket traffic.

Defensive priority

Defenders should prioritize verifying their Open WebUI version and upgrading to 0.11.0 if necessary.

Recommended defensive actions

  • Verify Open WebUI version and upgrade to 0.11.0 if necessary
  • Review automation recurrence configurations for potential impact
  • Monitor instance performance and event loop usage
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix in version 0.11.0. The vulnerability was caused by inefficient automation recurrence parsing in Open WebUI versions 0.9.0 to 0.10.0. The issue is fixed in version 0.11.0, which improves the computation of recurring events and prevents the event loop from being blocked. Defenders should verify their Open WebUI version and upgrade to 0.11.0 if necessary.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-70489 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-70489

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-70489 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70489

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.