Skip to content
Open WebUIGHSA-chf7-q7m5-fq92

Open WebUI Uncontrolled Resource Consumption vulnerability

High7.5CVE-2024-12537 · Published Mar 20, 2025 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
open-webui
PyPI
<= 0.3.32No fix yet
Details and references

In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint. If a malicious actor sends a POST request with an excessively high volume of content, the server could become completely unresponsive. This could lead to severe performance issues, causing the server to become unresponsive or experience significant degradation, ultimately resulting in service interruptions for legitimate users.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400, CWE-770
Also known as
CVE-2024-12537, PYSEC-2026-1728

More Open WebUI advisories

All Open WebUI
DateAdvisory
Mar 202025Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-12534High7.5no fix yet
Mar 202025Open WebUI has vulnerable dependency on starlette via fastapi
GHSA-w466-2wfc-8g58High7.5no fix yet
Mar 202025Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
CVE-2024-7044Medium6.8no fix yet
Mar 202025Open WebUI Allows Arbitrary File Reading and Deletion
CVE-2024-7043High8.1no fix yet
Mar 202025Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-7036High7.5no fix yet
Mar 202025Open WebUI Vulnerable to a Session Fixation Attack
CVE-2024-7053High7.6no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.