← Back

CVE-2024-12537

nvd nist
Published: Mar 20, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint. If a malicious actor sends a POST request with an excessively high volume of content, the server could become completely unresponsive. This could lead to severe performance issues, causing the server to become unresponsive or experience significant degradation, ultimately resulting in service interruptions for legitimate users.

Affected (1)

1 product
Open Webui
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.3.32

References (2)

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit

Timeline

No history available yet.