gradio is vulnerable to Regular Expression Denial of Service (ReDoS)
20
Low Risk
Affected versions of this package are vulnerable to a Regular Expression Denial of Service (ReDoS) in the remove_html_tags util function. A crafted input with patterns designed to trigger excessive backtracking in the regular expression can cause the function to consume excessive CPU resources, potentially leading to a denial of service.
You are affected if you are using a version that falls within the vulnerable range.
gradio is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.41.0 - 5.12.0.
Upgrade the gradio library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant