Executive brief
Open WebUI is a user interface for interacting with large language models. A flaw in how the system processes special 'skill' tags allows an attacker to freeze the entire application by sending a specially crafted chat message. This results in a complete service outage for all users until the system is manually restarted.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in 'backend/open_webui/utils/middleware.py' due to inefficient regex patterns (SKILL_MENTION_RE and strip_re) used to parse skill-mention tags. The patterns contain overlapping quantifiers that cause O(n²) backtracking when processing long strings that lack a closing bracket. Because these regex operations run synchronously on the main asyncio event loop, a single malicious request can block the entire uvicorn worker. An authenticated attacker can trigger this by sending a chat message with a specific prefix followed by a large volume of text. The issue is fixed in version 0.10.0 by optimizing the regex to use non-capturing groups that prevent catastrophic backtracking.
Affected products
- Open WebUI Open WebUI >= 0.9.2, < 0.10.0
Timeline
- 2026-06-29: disclosed
- 2026-07-09: advisory: NVD publication
- 2026-07-24: patched: GitHub Advisory published/updated