GHSA-5ccf-884p-4jjq

Suggest an improvement
Source
https://github.com/advisories/GHSA-5ccf-884p-4jjq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5ccf-884p-4jjq
Published
2025-03-20T12:32:51Z
Modified
2025-04-15T20:16:08.232629Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability
Details

A Denial of Service (DoS) vulnerability exists in open-webui/open-webui version 0.3.21. This vulnerability affects multiple endpoints, including /ollama/models/upload, /audio/api/v1/transcriptions, and /rag/api/v1/doc. The application processes multipart boundaries without authentication, leading to resource exhaustion. By appending additional characters to the multipart boundary, an attacker can cause the server to parse each byte of the boundary, ultimately leading to service unavailability. This vulnerability can be exploited remotely, resulting in high CPU and memory usage, and rendering the service inaccessible to legitimate users.

Database specific
{
    "github_reviewed": true,
    "nvd_published_at": "2025-03-20T10:15:50Z",
    "cwe_ids": [
        "CWE-400"
    ],
    "github_reviewed_at": "2025-03-21T03:38:57Z",
    "severity": "HIGH"
}
References

Affected packages

npm / open-webui

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.3.21

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json"

PyPI / open-webui

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.3.21

Affected versions

0.*
0.1.124
0.1.125
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.3.10
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.17.dev2
0.3.17.dev3
0.3.17.dev4
0.3.17.dev5
0.3.17
0.3.18
0.3.19
0.3.20
0.3.21

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json"