Authentication Flaw in Open-WebUI Affects Performance
CVE-2024-12537
What is CVE-2024-12537?
In version 0.3.32 of Open-WebUI, a critical security flaw exists due to the lack of authentication mechanisms. This vulnerability allows any unauthenticated attacker to send requests to the api/v1/utils/code/format endpoint. By submitting a POST request containing an excessively high volume of content, an attacker can overwhelm the server, leading to severe performance issues. This behavior may result in the server becoming unresponsive, significantly degrading performance, and causing prolonged service interruptions for legitimate users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
open-webui/open-webui <= unspecified
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
