PT-2025-12254 · Unknown+1 · @Gradio/Video+1
Published
2025-03-20
·
Updated
2025-03-20
·
CVE-2024-8966
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
gradio-app/gradio version @gradio/video@0.10.2
Description
A Denial of Service (DoS) attack is possible due to a vulnerability in the file upload process. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.
Recommendations
For version @gradio/video@0.10.2, consider restricting the size of file uploads or the number of characters allowed in multipart boundaries to prevent excessive processing and warnings. As a temporary workaround, consider implementing rate limiting or input validation to minimize the risk of exploitation.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gradio
@Gradio/Video