SOURCE-LINKED INTELLIGENCE
GHSA-5cpq-9538-jm2j: Gradio DOS in multipart boundry while uploading the file
A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2025-03-20T12:32:49.000Z
- OSV AI package advisories · 2026-07-07T14:34:57.483Z
First collected: 2026-09-19T20:28:21.856Z. This is not the publication date.