SOURCE-LINKED INTELLIGENCE
GHSA-hmx6-r76c-85g9: Gradio apps vulnerable to timing attacks to guess password
### Impact This security policy is with regards to a timing attack that allows users of Gradio apps to potentially guess the password of password-protected Gradio apps. This relies on the fact that string comparisons in Python terminate early, as soon as there is a string mismatch. Because Gradio apps are, by default, not rate-limited, a user could brute-force millions of guesses to figure out the correct username and password. ### Patches Yes, the problem has been patched in Gradio version 4.19.2 or higher. We have no knowledge of this exploit being used against users of Gradio applications,
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2024-02-22T22:09:22.000Z
- OSV AI package advisories · 2026-07-07T11:45:32.827Z
First collected: 2026-09-19T20:28:21.856Z. This is not the publication date.