PYPI · AUGUST 2026 · EARLY WARNING

Open WebUI Package Vulnerability: Denial of Service Threat

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
open webui (pypi)
Patched version
0.11.0
GHSA-2F54-P244-32Q6

An early warning has been issued for a denial of service vulnerability in the Open WebUI package. Users of versions prior to 0.11.0 are reportedly affected.

What happened

The Open WebUI package is under investigation for a vulnerability that allows any authenticated user to stall a worker by crafting a knowledge-search pattern that causes catastrophic backtracking. This results in a denial of service against other users of the affected worker. The vulnerability is tracked under GHSA-2F54-P244-32Q6 and was first flagged on 2026-08-04T20:56:23+00:00.

To assess your exposure, check if your deployment uses Open WebUI package versions prior to 0.11.0. If so, you are reportedly affected by this vulnerability. It is recommended to upgrade to version 0.11.0 or later to mitigate the risk.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If open webui is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are reportedly affected if you are using Open WebUI package versions prior to 0.11.0.

What should I do right now?

Identify and upgrade any instances of the Open WebUI package to version 0.11.0 or later.

Has this vulnerability been exploited in the wild?

There is no confirmed report of this vulnerability being exploited in the wild at this time.

Sources

Join the 0Day waitlist →

← Back to all threats