Open WebUIGHSA-9vf8-xgwm-97r8
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
High7.5CVE-2024-8053 · Published Mar 20, 2025 · updated Jul 7, 2026
In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload, potentially leading to server resource exhaustion and denial of service (DoS). Additionally, unauthorized users can misuse the endpoint to generate PDFs without verification, resulting in service misuse and potential operational and financial impacts.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| open-webui PyPI | <= 0.3.10 | No fix yet |
Details and references
More Open WebUI advisories
All Open WebUI| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability | High7.5 | No fix yet |
| Mar 202025 | Open WebUI denial of service through endpoint for converting markdown | High7.5 | No fix yet |
| Mar 202025 | Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions | High8.1 | 0.5.17 |
| Mar 202025 | Open WebUI stored cross-site scripting (XSS) vulnerability | High8.4 | No fix yet |
| Mar 202025 | Open WebUI Vulnerable to a Session Fixation Attack | High7.6 | No fix yet |
| Mar 202025 | Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/file | High7.5 | 0.4.7 |