Vulnerability PYSEC-2026-1412

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 07, 2026 at 02:34 PM UTC
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
4.0.0 - 5.0.0b1
4.0.0 - 5.0.0b1

Summary

Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb

Details

A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a maliciously crafted zip bomb, leading to a server crash and causing a denial of service.

Impacted packages

Timeline

Published
2 months ago
July 07, 2026 at 02:34 PM UTC
Last Modified
2 months ago
July 07, 2026 at 05:47 PM UTC