Infinite loop in Open WebUI - CVE-2026-87013
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an infinite loop in the folder re-parent handler and folder subtree walk when processing a folder parent cycle. A remote user can re-parent a folder under itself and send a request that traverses the folder to cause a denial of service.
Folders must be enabled and the acting role must have the folders feature permission.