Vulnerabilities/

Open WebUI Uncontrolled Resource Consumption vulnerability

Severity:
High

Description

In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-in process due to the lack of character length validation on these inputs.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
open-webui
Anything's wrong? Let us know Last updated on March 21, 2025