Description
In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-in process due to the lack of character length validation on these inputs.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.3.32
References
Could your website be exposed too?
SmartScanner can check your website for Open WebUI Uncontrolled Resource Consumption vulnerability and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Open WebUI Uncontrolled Resource Consumption vulnerability - open-webui - CVE-2024-12537
- graphql Uncontrolled Resource Consumption vulnerability - CVE-2023-26144
- Uncontrolled resource consumption in braces - CVE-2024-4068
- Uncontrolled Resource Consumption in trim-off-newlines - CVE-2021-23425


