CVE-2026-87012: Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
Calendar events carry a free-form meta object that is stored exactly as submitted, with no validation of the values inside it. The scheduler reads the per-event alert offset out of that object in a single pass that covers every user’s upcoming events, and compares it numerically without checking that it is a number. Any verified user could store a text value there, which made the comparison raise and abort the whole pass, so no calendar reminder fired for anyone on the instance while that event stayed inside the lookahead window.
References
- github.com/advisories/GHSA-v39v-59xw-j98g
- github.com/open-webui/open-webui/commit/abc69000b33b4894fbd97fc2c962139cf9a8d784
- github.com/open-webui/open-webui/pull/28790
- github.com/open-webui/open-webui/releases/tag/v0.11.1
- github.com/open-webui/open-webui/security/advisories/GHSA-v39v-59xw-j98g
- nvd.nist.gov/vuln/detail/CVE-2026-87012
Code Behaviors & Features
Detect and mitigate CVE-2026-87012 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →