Vulnerabilities/

Open WebUI Uncontrolled Resource Consumption vulnerability - open-webui

Severity:
High

Description

In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the api/v1/utils/code/format endpoint. If a malicious actor sends a POST request with an excessively high volume of content, the server could become completely unresponsive.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
open-webui
Anything's wrong? Let us know Last updated on April 01, 2025