Description
In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the api/v1/utils/code/format endpoint. If a malicious actor sends a POST request with an excessively high volume of content, the server could become completely unresponsive.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.3.32
References
Could your website be exposed too?
SmartScanner can check your website for Open WebUI Uncontrolled Resource Consumption vulnerability - open-webui and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Open WebUI Uncontrolled Resource Consumption vulnerability - CVE-2024-12534
- Uncontrolled resource consumption in braces - CVE-2024-4068
- graphql Uncontrolled Resource Consumption vulnerability - CVE-2023-26144
- Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability - Vulnerability


