CVE-2026-70489

MEDIUM

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

Title source: cna
STIX 2.1

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules at a fixed date of 2000-01-01 and then walked forward one interval at a time to find the next run. A single FREQ=MINUTELY rule enumerates roughly a quarter-century of occurrences synchronously on the event loop that also serves scheduler, HTTP, and WebSocket traffic, and the scheduler recomputes the next run for every claimed row on each poll. This causes availability impact for every other user of the instance. This issue is fixed in 0.11.0.

Scores

CVSS v3 6.5
EPSS 0.0029
EPSS Percentile 21.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-1333 CWE-400
Status published
Products (2)
open-webui/open-webui >= 0.9.0, < 0.11.0
pypi/open-webui 0.9.0 - 0.11.0PyPI
Published Aug 04, 2026
Tracked Since Aug 05, 2026