Open WebUIGHSA-6wj5-5pgr-jwq8
Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/file
High7.5Published Mar 20, 2025 · updated Apr 15, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| open-webui PyPI | < 0.4.7 | 0.4.7 |
Details and references
A vulnerability in open-webui/open-webui version 79778fa allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart boundary. By appending a large number of characters to the end of the multipart boundary, the server continuously processes each character, rendering the application inaccessible. This issue can prevent all users from accessing the application until the server recovers.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
More Open WebUI advisories
All Open WebUI| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Open WebUI Uncontrolled Resource Consumption vulnerability CVE-2024-12537High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Open WebUI Uncontrolled Resource Consumption vulnerability CVE-2024-12534High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Open WebUI has vulnerable dependency on starlette via fastapi GHSA-w466-2wfc-8g58High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload CVE-2024-7044Medium6.8no fix yet | Medium6.8 | No fix yet |
| Mar 202025 | Open WebUI Allows Arbitrary File Reading and Deletion CVE-2024-7043High8.1no fix yet | High8.1 | No fix yet |
| Mar 202025 | Open WebUI Uncontrolled Resource Consumption vulnerability CVE-2024-7036High7.5no fix yet | High7.5 | No fix yet |