logo

CVE-2024-10569 gradio

Package

Manager: pip
Name: gradio
Vulnerable Version: >=4.0.0 <=5.0.0b2

Severity

Level: High

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00129 pctl0.33052

Details

Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a maliciously crafted zip bomb, leading to a server crash and causing a denial of service.

Metadata

Created: 2025-03-20T12:32:39Z
Modified: 2025-03-20T20:37:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-7xmc-vhjp-qv5q/GHSA-7xmc-vhjp-qv5q.json
CWE IDs: ["CWE-475"]
Alternative ID: GHSA-7xmc-vhjp-qv5q
Finding: F008
Auto approve: 1