Authentication Flaw in Open-WebUI Affects Performance
CVE-2024-12537
Key Information:
- Vendor
Open-webui
- Status
- Vendor
- CVE Published:
- 20 March 2025
Badges
What is CVE-2024-12537?
In version 0.3.32 of Open-WebUI, a critical security flaw exists due to the lack of authentication mechanisms. This vulnerability allows any unauthenticated attacker to send requests to the api/v1/utils/code/format endpoint. By submitting a POST request containing an excessively high volume of content, an attacker can overwhelm the server, leading to severe performance issues. This behavior may result in the server becoming unresponsive, significantly degrading performance, and causing prolonged service interruptions for legitimate users.
Affected Version(s)
open-webui/open-webui <= unspecified
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
CVSS V3.0
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
