THREAT OPS › Threat News › [GHSA] GHSA-3g9q-v48f-hh9w (high) — Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
[GHSA] GHSA-3g9q-v48f-hh9w (high) — Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
GHSA-3g9q-v48f-hh9w Severity: high CVE: CVE-2026-87011
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
## Summary
The OIDC back-channel logout endpoint is unauthenticated by design, because the identity provider calls it without a browser session. Before checking whether the submitted logout token was genuine, the handler fetched the pr
Indicators of compromise
- CVE-2026-87011cve
Original source: https://github.com/advisories/GHSA-3g9q-v48f-hh9w