The full security policy now lives on the documentation site, so it only has to be kept up to date in one place. This file keeps a link to it and the one reporting channel we accept, since GitHub shows this file to reporters on the Security tab.
Good-faith reports that turn out not to be vulnerabilities are now explicitly welcomed, and the line about barring reporters is softened so it only targets repeated or deliberate rule breaking. The section on foreign CNAs moves near the end, dashes are gone, a few redundant sentences are cut and the last-updated date is today.
* fix: Direct Connection replies are saved scrambled or empty
With a Direct Connection the browser tab forwards the model's reply to the server piece by piece. Since the server started checking the tab's session again for every one of those pieces, the pieces could overtake each other while the checks ran, so the saved reply came out in the wrong order, or empty when the end of the stream arrived first. Pieces from one tab are now handled one after another in the order they arrived, and each one is still checked.
Fixes#31953
* fix: check Direct Connection reply pieces side by side while keeping them in order
Handling one tab's reply pieces strictly one after another also made each piece wait for the previous piece's session check, so a fast 2000-piece reply took 12 to 22% longer to save than without the ordering. Each piece's check now starts as soon as it arrives and only the hand-over waits its turn, so replies save as fast as before and still in order. Once a check fails, for example after a sign-out, no later piece from that tab gets through either.
On Qdrant, uploading a file into a knowledge base or editing a file's content could leave the knowledge base with only part of the file, often exactly 64 chunks, while the file showed as completed and nothing was logged. The file's chunks were saved without waiting for Qdrant to make them searchable, and the knowledge base copied them straight after, so it only got the ones Qdrant had finished storing. Saving now waits until Qdrant has finished storing the chunks, so the knowledge base always gets the whole file. On a busy Qdrant this makes file processing somewhat slower, since each save now waits for the server.
Fixes#31959
* i18n: fill in missing Hungarian translations
392 labels and messages had no Hungarian text, so Hungarian users saw them in English, for example on the user groups, two-factor sign-in, terminal and file compare screens. They are now all translated, keeping the vocabulary and informal tone of the existing Hungarian strings.
* i18n: translate the new authenticator sign-in strings for Hungarian (hu-HU)
* i18n: fill missing Dutch (nl-NL) translations
About 160 strings showed up in English for Dutch users, mostly on the new authenticator and recovery code screens, group inheritance in the admin panel, the file compare view and the starter prompt cards. All of them are translated now, using the words the Dutch file already uses for the same things, like "inloggen" for signing in and "beheerd" for managed. Counters such as remaining recovery codes and group member counts are worded so they still read correctly when the number is 1.
* i18n: translate the new authenticator sign-in strings for Dutch (nl-NL)
* i18n: fill missing sk-SK translations
About 2,800 interface texts had no Slovak translation, so Slovak users saw English across much of the app, including most of the newer settings pages. All of them are now translated, and variables like {{name}} and the Slovak plural variants are kept. Terminology follows the words the existing Slovak translation already uses, and no existing Slovak translation or other language was changed.
* i18n: translate the new authenticator sign-in strings for Slovak (sk-SK)
On the first day of a month, chats from the day before were listed under "Previous 7 days" in the sidebar instead of "Yesterday". The same happened on January 1st for chats from December 31st. Any chat from the previous calendar day is now listed under "Yesterday", whatever the month or year.
Fixes#31964
With the admin setting Web Search Confirmation on, switching on Web Search from the Integrations menu opened the confirmation popup while the menu stayed open behind it. The first click on Cancel or Continue only closed the menu, so the buttons looked broken until clicked a second time. The menu now closes when the popup opens, so one click confirms or cancels.
Fixes#31963
* i18n: fill missing Croatian translations
166 strings in the Croatian interface were still empty and showed up in English, among them the new multi-factor sign-in screens, the group hierarchy settings, file comparison and the default prompt suggestions on the chat start screen. They are now translated with the words the Croatian translation already uses elsewhere, for example "povezivanje" for connections and "vještina" for skills. Model parameter names such as top_k stay unchanged, same as in English.
* i18n: translate the new authenticator sign-in strings for Croatian (hr-HR)
When a model file was downloaded by URL in Manage Ollama, the end of the file could still be on its way to disk when Open WebUI sent it to Ollama, so Ollama got a cut-off copy. The download is now fully on disk before it is sent, so Ollama gets the whole file.
Fixes#31956
* i18n: fill missing Slovenian (sl-SI) translations
About 400 texts showed up in English for Slovenian users, mostly in newer areas like the file browser, terminal, group settings, multi-factor sign-in and the chat slash commands. All of them now have Slovenian text, using the same terms the rest of the Slovenian translation already uses. Texts that show a number without separate plural forms put the number after a colon, for example "Orodja: 5", so they read correctly whatever the count.
* i18n: translate the new authenticator sign-in strings for Slovenian (sl-SI)
* i18n: fill missing Czech translations
Czech users saw 167 texts in English, among them the new group hierarchy, the authenticator and recovery code setup, the file comparison and several web search settings. All of them are now translated, using the words the Czech translation already uses for chats, groups, connections and sign-in. Model parameter names like top_k are left untranslated, as in the other languages.
* i18n: translate the new authenticator sign-in strings for Czech (cs-CZ)
* i18n: fill missing German (de-DE) translations
German users saw English text in the new authenticator and recovery code screens, the parent group settings, the tool server list and a few other recently added places, because 74 labels and messages had no German translation yet. All of them are translated now, using the wording the rest of the German translation already uses for things like tools, groups and signing in.
* i18n: improve wording of new German (de-DE) translations
A few of the German texts for two-factor sign-in, group settings and connections were awkward or misleading. The remaining recovery codes counter used the plural form even for a single code, and the admin button that signs a user out on all devices sounded like it would sign out the admin. Both are fixed, along with smaller wording improvements across the German texts added in the previous commit.
* i18n: translate the new authenticator sign-in strings for German (de-DE)
When a model returned an image, only PNG was saved as a file. JPEG and WebP images stayed as raw base64 data inside the chat in the database, so a 1.5 MB JPEG made the stored chat 1.5 MB larger. These images are now saved as files and the chat keeps only a link to them, the same way PNG already worked.
Fixes#31916
About 2,800 of the 3,600 Romanian strings were still empty, so most of the interface showed in English. They are now all translated, reusing the wording the Romanian file already had for each term. Twelve older strings are also corrected, since they mistranslated three terms: embedding read as encapsulation, pipeline as a water pipe and code interpreter as a human interpreter. Left as they were, the same settings page would have shown two different words for each of these terms.
The inline citation markers in answers from external knowledge bases (Qdrant, Milvus, pgvector) showed the site's domain, for example docs.example.test, instead of the page title saved with each document. They now show that title, the same way a regular knowledge base shows the file name, and still fall back to the domain when a document has no title. Two different pages can share a title, so each marker now looks up its title by the page it points to; before, a repeated title made every later marker show the next page's title and the last one show nothing.
Fixes https://github.com/open-webui/open-webui/issues/31929
With Milvus as the vector database, all chunks of a file were sent to Milvus in one request. Large files exceeded Milvus's default 64 MB request size limit, so processing ran through the whole embedding step and then failed with the error RESOURCE_EXHAUSTED. With a 4096-dimension embedding model this already happened at about 4,000 chunks, which is a few MB of text. Chunks are now sent in batches of 128, with and without ENABLE_MILVUS_MULTITENANCY_MODE.
Fixes#31989
When a reply was paused and then picked up again, either by answering a question from the built-in Ask User tool or by pressing Continue, every tool round from the second one on sent everything from before the pause to the model twice. Providers that reject repeated tool calls, like DeepSeek, then fail with "Duplicate 'call_id'" and the chat stops, while others quietly see the earlier tool calls and text twice. Everything from before the pause is now sent exactly once. Tested against a mock provider that records every request: three tool rounds after an answered question and after Continue send everything once, and replies that were never paused send exactly what they sent before.
Fixes#31991