CVE-2024-12868 Information

Description

In version 0.3.32 of open-webui the application uses a vulnerable version of the starlette package through its dependency on fastapi. The starlette package versions <=0.49 are susceptible to uncontrolled resource consumption which can be exploited to cause a denial of service through memory exhaustion. This issue is addressed in fastapi version 0.115.3.

Reference

https://huntr.com/bounties/56175583-70e3-4d53-94de-3f3a8e2423ec

Share on: