HIGH 7.5 PyPI
Open WebUI denial of service through endpoint for converting markdown
GHSA-5v9m-57mq-qc75 · CVE-2024-7983
Published · Modified
Description
In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server to spend excessive time converting it, leading to a denial of service. The server becomes unresponsive to other requests until the conversion is complete.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-7983
- PACKAGE https://github.com/open-webui/open-webui
- WEB https://github.com/open-webui/open-webui/blob/eff736acd2e0bbbdd0eeca4cc209b216a1f23b6a/backend/apps/webui/routers/utils.py#L49
- WEB https://huntr.com/bounties/f8156ca5-1328-480f-a72b-8d3dfdad87dc
Ready to move
Start Securing
Free, no credit card | First findings in minutes