gradio is vulnerable to Denial of Service (DoS)
30
Low Risk
Affected versions of this package are vulnerable to Denial of Service (DoS) due to improper enforcement of file size limits during uploads. An attacker can bypass the user-defined max_file_size by uploading a file with an excessively long filename, potentially exhausting server resources. This patch resolves the issue by correctly passing the max_file_size to the MultiPartParser through the GradioMultiPartParser class.
You are affected if you are using a version that falls within the vulnerable range.
gradio is vulnerable to Denial of Service (DoS) in versions 4.0.0 - 5.34.2.
Upgrade the gradio library to the patch version or turn off overflow checking.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant