Description
In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-in process due to the lack of character length validation on these inputs.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.3.32
References
Related Issues
- Open WebUI Uncontrolled Resource Consumption vulnerability - open-webui - CVE-2024-12537
- graphql Uncontrolled Resource Consumption vulnerability - CVE-2023-26144
- Uncontrolled resource consumption in braces - CVE-2024-4068
- Uncontrolled Resource Consumption in trim-off-newlines - CVE-2021-23425
You might also like:
- Tags:
- npm
- open-webui
Anything's wrong? Let us know Last updated on March 21, 2025


