PT-2025-12254 · Unknown+1 · @Gradio/Video+1

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-8966

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions gradio-app/gradio version @gradio/video@0.10.2
Description A Denial of Service (DoS) attack is possible due to a vulnerability in the file upload process. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.
Recommendations For version @gradio/video@0.10.2, consider restricting the size of file uploads or the number of characters allowed in multipart boundaries to prevent excessive processing and warnings. As a temporary workaround, consider implementing rate limiting or input validation to minimize the risk of exploitation.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8966
GHSA-5CPQ-9538-JM2J
GHSA-HH3J-9M59-P8VC

Affected Products

Gradio
@Gradio/Video