Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7xmc-vhjp-qv5q

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb

A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a maliciously crafted zip bomb, leading to a server crash and causing a denial of service.

Пакеты

Наименование

gradio

pip
Затронутые версииВерсия исправления

>= 4.0.0, <= 5.0.0b2

Отсутствует

EPSS

Процентиль: 37%
0.00158
Низкий

7.5 High

CVSS3

Дефекты

CWE-475

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a maliciously crafted zip bomb, leading to a server crash and causing a denial of service.

EPSS

Процентиль: 37%
0.00158
Низкий

7.5 High

CVSS3

Дефекты

CWE-475