logo

CVE-2024-7036 open-webui

Package

Manager: pip
Name: open-webui
Vulnerable Version: >=0 <=0.3.8

Severity

Level: High

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00171 pctl0.3885

Details

Open WebUI Uncontrolled Resource Consumption vulnerability A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causing the Admin panel to become unresponsive. This prevents administrators from performing essential user management actions such as deleting, editing, or adding users. The vulnerability can also be exploited by authenticated users with low privileges, leading to the same unresponsive state in the Admin panel.

Metadata

Created: 2025-03-20T12:32:45Z
Modified: 2025-07-21T19:08:55Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-wcwp-9rcp-jvfg/GHSA-wcwp-9rcp-jvfg.json
CWE IDs: ["CWE-400"]
Alternative ID: GHSA-wcwp-9rcp-jvfg
Finding: F067
Auto approve: 1