{"id":"GHSA-w466-2wfc-8g58","aliases":[],"url":"https://o3.security/vulnerability/GHSA-w466-2wfc-8g58","summary":"Open WebUI has vulnerable dependency on starlette via fastapi","details":"In version 0.3.32 of open-webui, the application uses a vulnerable version of the starlette package through its dependency on fastapi. The starlette package versions <=0.49 are susceptible to uncontrolled resource consumption, which can be exploited to cause a denial of service through memory exhaustion. This issue is addressed in fastapi version 0.115.3.","published":"2025-03-20T12:32:44Z","modified":"2025-04-15T19:59:07.553396Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"open-webui","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/encode/starlette/security/advisories/GHSA-f96h-pmfr-66vw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47874"},{"type":"PACKAGE","url":"https://github.com/open-webui/open-webui"},{"type":"WEB","url":"https://huntr.com/bounties/56175583-70e3-4d53-94de-3f3a8e2423ec"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-04-15T19:59:07.553396Z"}}