Vulnerability PYSEC-2026-1412
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 07, 2026 at 02:34 PM UTC
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
4.0.0 - 5.0.0b1
4.0.0 - 5.0.0b1
Summary
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
Details
A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a maliciously crafted zip bomb, leading to a server crash and causing a denial of service.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
2 months ago
Gradio CORS Origin Validation Bypass Vulnerability
5.0.0 - 5.29.1 PYSEC-2026-1423
5.0.0 - 5.29.1 PYSEC-2026-1423
High Risk
2 months ago
Gradio DOS in multipart boundry while uploading the file
0.1.0 - 5.22.0 PYSEC-2026-1410
0.1.0 - 5.22.0 PYSEC-2026-1410
Medium Risk
2 months ago
Gradio Vulnerable to Open Redirect
0.1.0 - 4.37.2 PYSEC-2026-1411
0.1.0 - 4.37.2 PYSEC-2026-1411
Medium Risk
2 months ago
Gradio Path Traversal vulnerability
0.1.0 - 5.0.1 PYSEC-2026-1418
0.1.0 - 5.0.1 PYSEC-2026-1418
High Risk
2 months ago
Gradio Vulnerable to Arbitrary File Deletion
4.0.0 - 5.0.0b1 PYSEC-2026-1417
4.0.0 - 5.0.0b1 PYSEC-2026-1417
Impacted packages
Timeline
Published
2 months ago
July 07, 2026 at 02:34 PM UTC
Last Modified
2 months ago
July 07, 2026 at 05:47 PM UTC