CVE-2024-12534
HIGHopen-webui v0.3.32 - Unauthenticated Denial of Service via Large Payload Submission
Title source: llmDescription
In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-in process due to the lack of character length validation on these inputs. This vulnerability can lead to a Denial of Service (DoS) condition when a user submits excessively large strings, exhausting server resources such as CPU, memory, and disk space, and rendering the service unavailable for legitimate users. This makes the server susceptible to resource exhaustion attacks without requiring authentication.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/c7c0a4e6-acd3-49b4-8684-2c2c27014b76
Scores
CVSS v3
7.5
EPSS
0.0062
EPSS Percentile
70.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (3)
npm/open-webui
0npm
openwebui/open_webui
0.3.32
pypi/open-webui
0PyPI
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026