Open WebUIGHSA-wcwp-9rcp-jvfg
Open WebUI Uncontrolled Resource Consumption vulnerability
High7.5CVE-2024-7036 · Published Mar 20, 2025 · updated Jul 7, 2026
A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causing the Admin panel to become unresponsive. This prevents administrators from performing essential user management actions such as deleting, editing, or adding users. The vulnerability can also be exploited by authenticated users with low privileges, leading to the same unresponsive state in the Admin panel.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| open-webui PyPI | <= 0.3.8 | No fix yet |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- CVE-2024-7036, PYSEC-2026-1742
More Open WebUI advisories
All Open WebUI| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability | High7.5 | No fix yet |
| Mar 202025 | Open WebUI denial of service through endpoint for converting markdown | High7.5 | No fix yet |
| Mar 202025 | Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint | High7.5 | No fix yet |
| Mar 202025 | Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions | High8.1 | 0.5.17 |
| Mar 202025 | Open WebUI stored cross-site scripting (XSS) vulnerability | High8.4 | No fix yet |
| Mar 202025 | Open WebUI Vulnerable to a Session Fixation Attack | High7.6 | No fix yet |