Description
A Denial of Service (DoS) vulnerability exists in open-webui/open-webui version 0.3.21. This vulnerability affects multiple endpoints, including /ollama/models/upload, /audio/api/v1/transcriptions, and /rag/api/v1/doc. The application processes multipart boundaries without authentication, leading to resource exhaustion.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.3.21
References
Could your website be exposed too?
SmartScanner can check your website for Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Denial of Service (DoS) vulnerability in RSSHub - CVE-2022-31110
- Open WebUI Uncontrolled Resource Consumption vulnerability - CVE-2024-12534
- Open WebUI Uncontrolled Resource Consumption vulnerability - open-webui - CVE-2024-12537
- prismjs Regular Expression Denial of Service vulnerability - CVE-2021-3801


