Open-WebUI Name Field Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Open-WebUI version 0.3.8. The issue allows an unauthenticated attacker to disrupt the Admin panel by entering excessively large text in the 'name' field during the sign-up process. This overloads the system, causing the Admin panel to become unresponsive and hindering administrators from managing users effectively, including actions like deleting, editing, or adding users. Additionally, authenticated users with low privileges can exploit this vulnerability to achieve the same disruptive effect in the Admin panel.

Impact

Exploitation of this vulnerability causes the Admin panel to freeze, disrupting user management tasks such as adding, editing, or deleting users.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.0
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.