GradioGHSA-5cpq-9538-jm2j
Gradio DOS in multipart boundry while uploading the file
High7.5CVE-2024-8966 · Published Mar 20, 2025 · updated Jul 7, 2026
A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gradio PyPI | <= 5.22.0 | No fix yet |
Details and references
More Gradio advisories
All Gradio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Gradio Vulnerable to Open Redirect | Medium5.4 | No fix yet |
| Mar 202025 | Gradio Path Traversal vulnerability | Medium5.3 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb | High7.5 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Arbitrary File Deletion | High8.2 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request | High7.5 | No fix yet |
| Jan 142025 | Gradio Blocked Path ACL Bypass Vulnerability | Critical | 5.11.0 |