CVE-2026-59220

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/07/2026
Last modified:
10/07/2026

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKILL_MENTION_RE and strip_re regular expressions in backend/open_webui/utils/middleware.py parsed skill mentions with overlapping quantifiers, allowing an authenticated chat message containing to trigger quadratic backtracking and block the asyncio event loop. This issue is fixed in version 0.10.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:* 0.9.2 (including) 0.10.0 (excluding)