Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability
- Severity:
- High
Description
A Denial of Service (DoS) vulnerability exists in open-webui/open-webui version 0.3.21. This vulnerability affects multiple endpoints, including /ollama/models/upload, /audio/api/v1/transcriptions, and /rag/api/v1/doc. The application processes multipart boundaries without authentication, leading to resource exhaustion.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.3.21
References
Related Issues
- Denial of Service (DoS) vulnerability in RSSHub - CVE-2022-31110
- Open WebUI Uncontrolled Resource Consumption vulnerability - CVE-2024-12534
- Open WebUI Uncontrolled Resource Consumption vulnerability - open-webui - CVE-2024-12537
- prismjs Regular Expression Denial of Service vulnerability - CVE-2021-3801
You might also like:
- Tags:
- npm
- open-webui
Anything's wrong? Let us know Last updated on April 15, 2025


