We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a maliciously crafted zip bomb, leading to a server crash and causing a denial of service.
Reserved 2024-10-30 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_aiCWE-475 Undefined Behavior for Input to API
huntr.com/bounties/7192bcbb-08a3-4d22-a321-9c6d19dbfc74
Support options