CVE-2024-7999

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 400

Summary

CVE-2024-7999 is a Denial of Service (DoS) vulnerability affecting open-webui version 79778fa. An attacker can exploit this issue by uploading a file with a malformed multipart boundary, causing the server to continuously process each character appended to the boundary. This results in the application becoming inaccessible to all users, preventing them from accessing it until the server recovers. The vulnerability allows an attacker to cause significant disruption to the availability of the application.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share