THREAT OPS › Threat News › [GHSA] GHSA-3cgp-3cqx-j8w2 (medium) — Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
[GHSA] GHSA-3cgp-3cqx-j8w2 (medium) — Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
GHSA-3cgp-3cqx-j8w2 Severity: medium CVE: CVE-2026-88000
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
## Summary Chat histories are stored as an unvalidated JSON object. After a message is deleted, the code that picks the chat's new current message walked down the `childrenIds` links without recording where it had already been. Any account wit
Indicators of compromise
- b933292d63d12be3fd1416fe55519ddc7aa336bcsha1
- CVE-2026-88000cve
Original source: https://github.com/advisories/GHSA-3cgp-3cqx-j8w2