NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4851 most downloaded on PyPI
Open WebUI
Last release 17 days ago
31 Aug 2026
Ships on a steady schedule
a new release about every 3 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
165 releases · first in 2024
We recommend updating production deployments at your earliest convenience. Not all security fixes in this version may be enumerated in the fixed secti…
Note truncated.
One column per month.
We recommend updating production deployments at your earliest convenience. Not all security fixes in this version may be enumerated in the fixed secti…
🛡️ Redirect-based SSRF protection. All outbound HTTP requests now block 3xx redirects by default via a new AIOHTTP_CLIENT_ALLOW_REDIRECTS environment
AIOHTTP_CLIENT_ALLOW_REDIRECTS environment variable, preventing redirect-based SSRF where a public URL silently redirects to internal addresses (RFC 1918, loopback, cloud-metadata endpoints). Affected call sites include web fetch, image loading, OAuth discovery, tool server execution, and code interpreter login. #24491IFRAME_CSP environment variable, restricting what LLM-generated or user-uploaded HTML can load and execute inside previews. CommitTERMINAL_PROXY_HEADERS environment variable (JSON object), enabling deployment-specific security headers like sandbox policies for proxied content. Commitis_pinned being passed to the SQLAlchemy model on create, and passed twice to NoteResponse on read. #24484, #24486sharing.public_skills permission, preventing non-admin users from making skills publicly accessible without the required permission. #24494sharing.public_calendars permission, preventing users from making calendars publicly readable or writable without explicit admin-granted sharing permission. #24493user_id field through mass-assignment, preventing authenticated users from attributing ratings to other users and corrupting Elo leaderboard rankings and admin feedback exports. #24508process_file and process_files_batch retrieval endpoints now enforce collection write-access checks before embedding content, preventing authenticated users from injecting file content into another user's knowledge-base collection. #24524workspace.tools or workspace.tools_import permission, preventing users with only a write-access grant from overwriting executable tool code while still allowing metadata edits. #24513validate_url() before fetching, aligning the defense-in-depth posture with sibling image-loading paths. #24518params dict (including system prompts) from responses to callers without write access, preventing read-only users from viewing admin-curated model configuration. #24525PROFILE_IMAGE_ALLOWED_MIME_TYPES) and sets X-Content-Type-Options: nosniff, preventing stored-XSS through SVG or other executable content types. CommitGET /api/v1/retrieval/ status endpoint has been removed as dead code — retrieval configuration is already available through authenticated admin endpoints. #24497📜 Chat scroll position on load. Opening a chat conversation now reliably scrolls to the bottom of the message history, fixing a regression caused by c
content-visibility: auto where estimated element sizes prevented the initial scroll from reaching the true bottom.🔇 Voice Mode mute control. Voice Mode now includes a dedicated mute toggle with an "M" shortcut and auto-unmute after assistant playback, so you can p
replace flag on the embeds event, enabling live dashboards and progress panels that update without stacking duplicate entries.<think> tags inside the content field, preventing raw markup from leaking into chat output for models whose templates don't strip think tags (e.g. Gemma 4). #23844🔑 Brotli dependency update. Brotli has been updated to address CVE-2025-6176 .
reminder_minutes parameter, allowing models to set custom reminder durations instead of the default 10-minute notification.CUSTOM_API_KEY_HEADER environment variable, enabling compatibility with reverse proxies that use the Authorization header for their own authentication.<$skillId|label> message tags is now handled server-side, and tags are stripped before messages reach the model.sslmode, options, and target_session_attrs without any stripping or conversion.UV_LINK_MODE=copy is now set in the Dockerfile to force reliable file installation.fetch_url built-in tool now safely handles None content returned by web loaders instead of crashing with a TypeError.WWW-Authenticate header doesn't contain a resource_metadata link, improving compatibility with more MCP server implementations.Authorization headers by falling back to cookie and request state tokens, preventing errors when used behind forward-auth proxies.[context] or {{CONTEXT}} placeholders, helping administrators avoid accidental redundant context injection.create_automation tool now correctly detects the current model ID even when model_id is not yet set in metadata, falling back to the model dict.resource content type are now correctly detected and their resource.text payload is extracted, instead of being silently ignored.content-visibility: auto, letting the browser natively skip rendering of off-screen messages without destroying component trees. This eliminates scroll jump artifacts and mount/destroy thrashing while preserving memory efficiency in long conversations.client_name support more gracefully, preventing connection errors with certain Redis configurations.asyncpg to psycopg (v3). This is a transparent change for most deployments, but custom connection strings with asyncpg-specific parameters may need adjustment.🐛 Missing `aiosqlite` dependency. Fixed a startup crash (ModuleNotFoundError: No module named 'aiosqlite') when installing Open WebUI via pip or uv by
aiosqlite dependency. Fixed a startup crash (ModuleNotFoundError: No module named 'aiosqlite') when installing Open WebUI via pip or uv by adding the missing aiosqlite package to pyproject.toml. The dependency was listed in requirements.txt but not in the published package metadata, so it was not installed automatically. #23916asyncpg dependency. Added the missing asyncpg package to pyproject.toml to prevent the same startup crash for PostgreSQL users. Like aiosqlite, it was present in requirements.txt but absent from the published package dependencies.Your coding agent can read these notes before it upgrades. Set up the MCP server →