Open WebUIGHSA-5v9m-57mq-qc75
Open WebUI denial of service through endpoint for converting markdown
High7.5CVE-2024-7983 · Published Mar 20, 2025 · updated Jul 7, 2026
In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server to spend excessive time converting it, leading to a denial of service. The server becomes unresponsive to other requests until the conversion is complete.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| open-webui PyPI | <= 0.3.8 | No fix yet |
Details and references
More Open WebUI advisories
All Open WebUI| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability | High7.5 | No fix yet |
| Mar 202025 | Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint | High7.5 | No fix yet |
| Mar 202025 | Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions | High8.1 | 0.5.17 |
| Mar 202025 | Open WebUI stored cross-site scripting (XSS) vulnerability | High8.4 | No fix yet |
| Mar 202025 | Open WebUI Vulnerable to a Session Fixation Attack | High7.6 | No fix yet |
| Mar 202025 | Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/file | High7.5 | 0.4.7 |