Open WebUI Uncontrolled Resource Consumption vulnerability - open-webui
- Severity:
- High
Description
In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the api/v1/utils/code/format endpoint. If a malicious actor sends a POST request with an excessively high volume of content, the server could become completely unresponsive.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.3.32
References
Related Issues
- Open WebUI Uncontrolled Resource Consumption vulnerability - CVE-2024-12534
- Uncontrolled resource consumption in braces - CVE-2024-4068
- graphql Uncontrolled Resource Consumption vulnerability - CVE-2023-26144
- Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability - Vulnerability
You might also like:
- Tags:
- npm
- open-webui
Anything's wrong? Let us know Last updated on April 01, 2025


