PatchSiren cyber security CVE debrief
CVE-2026-70489 open-webui CVE debrief
Open WebUI, a self-hosted AI platform, had a vulnerability in versions 0.9.0 to 0.10.0 where automation recurrence parsing could cause significant availability impact. The issue, fixed in version 0.11.0, involved inefficient computation of recurring events that could block the event loop used for scheduler, HTTP, and WebSocket traffic. This could lead to performance degradation and potential downtime for users of the instance. Defenders should be aware of the potential impact and take steps to verify and mitigate the vulnerability.
- Vendor
- open-webui
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-04
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-08-04
- Advisory updated
- 2026-09-18
Who should care
Defenders managing Open WebUI instances should verify their version and upgrade to 0.11.0 if necessary to prevent potential availability impact. This includes operators, platform administrators, and security teams responsible for maintaining the instance. They should be aware of the potential impact and take steps to verify and mitigate the vulnerability.
Why it matters
Defenders managing Open WebUI instances should verify their version and upgrade to 0.11.0 if necessary to prevent potential availability impact due to inefficient automation recurrence parsing.
- Potential availability impact for users of the instance
- Inefficient computation of recurring events could block the event loop
- Verification of Open WebUI version and upgrade to 0.11.0 is necessary
Technical summary
The vulnerability in Open WebUI versions 0.9.0 to 0.10.0 causes availability impact due to inefficient automation recurrence parsing. The issue is fixed in version 0.11.0, which improves the computation of recurring events and prevents the event loop from being blocked. This fix should prevent potential downtime and performance degradation for users of the instance. The vulnerability is caused by the inefficient computation of recurring events, which can block the event loop used for scheduler, HTTP, and WebSocket traffic.
Defensive priority
Defenders should prioritize verifying their Open WebUI version and upgrading to 0.11.0 if necessary.
Recommended defensive actions
- Verify Open WebUI version and upgrade to 0.11.0 if necessary
- Review automation recurrence configurations for potential impact
- Monitor instance performance and event loop usage
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix in version 0.11.0. The vulnerability was caused by inefficient automation recurrence parsing in Open WebUI versions 0.9.0 to 0.10.0. The issue is fixed in version 0.11.0, which improves the computation of recurring events and prevents the event loop from being blocked. Defenders should verify their Open WebUI version and upgrade to 0.11.0 if necessary.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-70489 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-70489
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-70489 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70489
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/open-webui/open-webui/commit/c4ae8c86786fed521960466f6d8eef8af22c2946
-
Source reference
Unverified legacy reference
URL: https://github.com/open-webui/open-webui/releases/tag/v0.11.0
-
Source reference
Unverified legacy reference
URL: https://github.com/open-webui/open-webui/security/advisories/GHSA-73cq-mcgh-379c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.