Skip to content
Open WebUIGHSA-6wj5-5pgr-jwq8

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/file

High7.5Published Mar 20, 2025 · updated Apr 15, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
open-webui
PyPI
< 0.4.70.4.7
Details and references

A vulnerability in open-webui/open-webui version 79778fa allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart boundary. By appending a large number of characters to the end of the multipart boundary, the server continuously processes each character, rendering the application inaccessible. This issue can prevent all users from accessing the application until the server recovers.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400

More Open WebUI advisories

All Open WebUI
DateAdvisory
Mar 202025Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-12537High7.5no fix yet
Mar 202025Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-12534High7.5no fix yet
Mar 202025Open WebUI has vulnerable dependency on starlette via fastapi
GHSA-w466-2wfc-8g58High7.5no fix yet
Mar 202025Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
CVE-2024-7044Medium6.8no fix yet
Mar 202025Open WebUI Allows Arbitrary File Reading and Deletion
CVE-2024-7043High8.1no fix yet
Mar 202025Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-7036High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.