Vulnerabilities/

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability

Severity:
High

Description

A Denial of Service (DoS) vulnerability exists in open-webui/open-webui version 0.3.21. This vulnerability affects multiple endpoints, including /ollama/models/upload, /audio/api/v1/transcriptions, and /rag/api/v1/doc. The application processes multipart boundaries without authentication, leading to resource exhaustion.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
open-webui
Anything's wrong? Let us know Last updated on April 15, 2025