THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3g9q-v48f-hh9w (high) — Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

[GHSA] GHSA-3g9q-v48f-hh9w (high) — Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

medgithub_advisoriesPublished 2026-09-10

GHSA-3g9q-v48f-hh9w Severity: high CVE: CVE-2026-87011

Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

## Summary

The OIDC back-channel logout endpoint is unauthenticated by design, because the identity provider calls it without a browser session. Before checking whether the submitted logout token was genuine, the handler fetched the pr

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3g9q-v48f-hh9w