Vulnerability PYSEC-2026-1410
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 07, 2026 at 02:34 PM UTC
Gradio DOS in multipart boundry while uploading the file
0.1.0 - 5.22.0
0.1.0 - 5.22.0
Summary
Gradio DOS in multipart boundry while uploading the file
Details
A vulnerability in the file upload process of gradio-app/gradio version @gradio/[email protected] allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
2 months ago
Gradio CORS Origin Validation Bypass Vulnerability
5.0.0 - 5.29.1 PYSEC-2026-1423
5.0.0 - 5.29.1 PYSEC-2026-1423
Medium Risk
2 months ago
Gradio Vulnerable to Open Redirect
0.1.0 - 4.37.2 PYSEC-2026-1411
0.1.0 - 4.37.2 PYSEC-2026-1411
Medium Risk
2 months ago
Gradio Path Traversal vulnerability
0.1.0 - 5.0.1 PYSEC-2026-1418
0.1.0 - 5.0.1 PYSEC-2026-1418
High Risk
2 months ago
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
4.0.0 - 5.0.0b1 PYSEC-2026-1412
4.0.0 - 5.0.0b1 PYSEC-2026-1412
High Risk
2 months ago
Gradio Vulnerable to Arbitrary File Deletion
4.0.0 - 5.0.0b1 PYSEC-2026-1417
4.0.0 - 5.0.0b1 PYSEC-2026-1417
Impacted packages
Timeline
Published
2 months ago
July 07, 2026 at 02:34 PM UTC
Last Modified
2 months ago
July 07, 2026 at 05:47 PM UTC