Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6983 | Open WebUI has vulnerable dependency on starlette via fastapi |
No reference.
Tue, 15 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In version 0.3.32 of open-webui, the application uses a vulnerable version of the starlette package through its dependency on fastapi. The starlette package versions <=0.49 are susceptible to uncontrolled resource consumption, which can be exploited to cause a denial of service through memory exhaustion. This issue is addressed in fastapi version 0.115.3. | ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-47874. Notes: All CVE users should reference CVE-2024-47874 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage. |
| Title | Denial of Service through Memory Exhaustion in open-webui/open-webui | |
| Weaknesses | CWE-400 | |
| References |
|
|
| Metrics |
cvssV3_0
|
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In version 0.3.32 of open-webui, the application uses a vulnerable version of the starlette package through its dependency on fastapi. The starlette package versions <=0.49 are susceptible to uncontrolled resource consumption, which can be exploited to cause a denial of service through memory exhaustion. This issue is addressed in fastapi version 0.115.3. | |
| Title | Denial of Service through Memory Exhaustion in open-webui/open-webui | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_0
|
Subscriptions
No data.
Status: REJECTED
Assigner: @huntr_ai
Published:
Updated: 2025-04-15T15:56:09.879Z
Reserved: 2024-12-20T20:02:03.628Z
Link: CVE-2024-12868
Updated:
Status : Rejected
Published: 2025-03-20T10:15:30.960
Modified: 2025-04-15T16:15:21.850
Link: CVE-2024-12868
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD