Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5cpq-9538-jm2j

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Gradio DOS in multipart boundry while uploading the file

A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.

Пакеты

Наименование

gradio

pip
Затронутые версииВерсия исправления

<= 5.22.0

Отсутствует

EPSS

Процентиль: 45%
0.00221
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.

EPSS

Процентиль: 45%
0.00221
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770