Miggo Predictive Vulnerability Database
Comprehensive vulnerability intelligence for security teams to gain clarity into CVEs to prioritize and respond with precision.
Concerned about an active attack path? Talk to our security experts and see Miggo in action
Contact UsTop 10 CVEs
New vulnerabilities last 30 days
CVE-2026-88000: Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Open WebUI DoS via message deletion in a cyclic chat tree causes an infinite loop in the chats.py backend, hanging the server and blocking all user requests.
Analysis:
Available
6.5
medium
9/9/2026
CVE-2026-88001: Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Open WebUI SSRF via unvalidated HTTP redirects in web fetches bypasses filters, granting authenticated users access to internal networks and cloud services.
Analysis:
Available
5
medium
9/9/2026
CVE-2026-88002: Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Open WebUI DoS via cyclic chat history from authenticated users triggers a non-terminating walk in message reconstruction, blocking the async event loop.
Analysis:
Available
6.5
medium
9/9/2026
CVE-2026-59185: Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
Identrail cross-tenant IDOR in its GitHub connect API grants attackers private repo access by binding a victim's unverified installation_id to their workspace.
Analysis:
Available
8.5
high
9/9/2026