<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:57:17 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-44552 — Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Pois…</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-44552</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; open-webui&lt;/p&gt;
&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix. When two or more Open WebUI instances share a Redis database (a supported and documented deployment pattern, e.g., for multi-region deployments, blue-green setups, or cluster topologies), the unprefixed keys collide. An admin on Instance A writing to tool_servers overwrites the value read by Instance B — causing Instance B&amp;#39;s users to receive Instance A&amp;#39;s tool server configuration. This vulnerability is fixed in 0.9.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; open-webui&lt;/p&gt;
&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix. When two or more Open WebUI instances share a Redis database (a supported and documented deployment pattern, e.g., for multi-region deployments, blue-green setups, or cluster topologies), the unprefixed keys collide. An admin on Instance A writing to tool_servers overwrites the value read by Instance B — causing Instance B&amp;#39;s users to receive Instance A&amp;#39;s tool server configuration. This vulnerability is fixed in 0.9.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-44552</guid>
    </item>
    <item>
      <title>GHSA-3x8w-4f7p-xxc2 — Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Pois…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3x8w-4f7p-xxc2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;# Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;Tool server and terminal server Redis cache:
- `backend/open_webui/utils/tools.py` (line 841, tool_servers SET)
- `backend/open_webui/utils/tools.py` (line 850, tool_servers GET)
- `backend/open_webui/utils/tools.py` (line 976, terminal_servers SET)
- `backend/open_webui/utils/tools.py` (line 986, terminal_servers GET)&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;Current main branch (commit `6fdd19bf1`) and likely all versions since the tool server / terminal server Redis cache was introduced.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;Open WebUI uses a `REDIS_KEY_PREFIX` (default `open-webui`) to namespace Redis keys, allowing multiple instances to safely share a single Redis backend. Every Redis key in the codebase uses this prefix — except the `tool_servers` and `terminal_servers` keys in `utils/tools.py`, which use bare key names.&lt;/p&gt;
&lt;p&gt;When two or more Open WebUI instances share a Redis database (a supported and documented deployment pattern, e.g., for multi-region deployments, blue-green setups, or cluster topologies), the unprefixed keys collide. An admin on Instance A writing to `tool_servers` overwrites the value read by Instance B — causing Instance B&amp;#39;s users to receive Instance A&amp;#39;s tool server configuration.&lt;/p&gt;
&lt;p&gt;```python
# utils/tools.py — unprefixed keys (problem)
await request.app.state.redis.set(&amp;#39;tool_servers&amp;#39;, ...)        # line 841
json.loads(await request.app.state.redis.get(…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;# Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;Tool server and terminal server Redis cache:
- `backend/open_webui/utils/tools.py` (line 841, tool_servers SET)
- `backend/open_webui/utils/tools.py` (line 850, tool_servers GET)
- `backend/open_webui/utils/tools.py` (line 976, terminal_servers SET)
- `backend/open_webui/utils/tools.py` (line 986, terminal_servers GET)&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;Current main branch (commit `6fdd19bf1`) and likely all versions since the tool server / terminal server Redis cache was introduced.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;Open WebUI uses a `REDIS_KEY_PREFIX` (default `open-webui`) to namespace Redis keys, allowing multiple instances to safely share a single Redis backend. Every Redis key in the codebase uses this prefix — except the `tool_servers` and `terminal_servers` keys in `utils/tools.py`, which use bare key names.&lt;/p&gt;
&lt;p&gt;When two or more Open WebUI instances share a Redis database (a supported and documented deployment pattern, e.g., for multi-region deployments, blue-green setups, or cluster topologies), the unprefixed keys collide. An admin on Instance A writing to `tool_servers` overwrites the value read by Instance B — causing Instance B&amp;#39;s users to receive Instance A&amp;#39;s tool server configuration.&lt;/p&gt;
&lt;p&gt;```python
# utils/tools.py — unprefixed keys (problem)
await request.app.state.redis.set(&amp;#39;tool_servers&amp;#39;, ...)        # line 841
json.loads(await request.app.state.redis.get(…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3x8w-4f7p-xxc2</guid>
    </item>
  </channel>
</rss>
