We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-10569

Zip Bomb Vulnerability in gradio-app/gradio



Description

A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a maliciously crafted zip bomb, leading to a server crash and causing a denial of service.

Reserved 2024-10-30 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


HIGH: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-475 Undefined Behavior for Input to API

Product status

Any version
affected

References

huntr.com/bounties/7192bcbb-08a3-4d22-a321-9c6d19dbfc74

cve.org (CVE-2024-10569)

nvd.nist.gov (CVE-2024-10569)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-10569

Support options

Helpdesk Chat, Email, Knowledgebase