VYPR
High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026

CVE-2024-7983

CVE-2024-7983

Description

In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server to spend excessive time converting it, leading to a denial of service. The server becomes unresponsive to other requests until the conversion is complete.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
open-webuiPyPI
<= 0.3.8

Affected products

3
  • cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*
    • (no CPE)range: unspecified
  • ghsa-coords
    Range: <= 0.3.8

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.