Skip to content
GradioGHSA-5cpq-9538-jm2j

Gradio DOS in multipart boundry while uploading the file

High7.5CVE-2024-8966 · Published Mar 20, 2025 · updated Jul 7, 2026

A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
<= 5.22.0No fix yet
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400, CWE-770
Also known as
CVE-2024-8966, PYSEC-2026-1410

More Gradio advisories

All Gradio
Advisory
Gradio Vulnerable to Open Redirect
Medium5.4Mar 20, 2025
Gradio Path Traversal vulnerability
Medium5.3Mar 20, 2025
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
High7.5Mar 20, 2025
Gradio Vulnerable to Arbitrary File Deletion
High8.2Mar 20, 2025
Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
High7.5Mar 20, 2025
Gradio Blocked Path ACL Bypass Vulnerability
CriticalJan 14, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.