5.23.3
6 years ago
3 hours ago
Known vulnerabilities in the gradio package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
gradio is a Python library for easily interacting with trained machine learning models Affected versions of this package are vulnerable to Path Equivalence due to the How to fix Path Equivalence? There is no fixed version for | [0,) |
gradio is a Python library for easily interacting with trained machine learning models Affected versions of this package are vulnerable to Open Redirect. The How to fix Open Redirect? There is no fixed version for | [0,) |
gradio is a Python library for easily interacting with trained machine learning models Affected versions of this package are vulnerable to Denial of Service (DoS) through the file upload process. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render the system inaccessible for extended periods, disrupting services and causing significant downtime. How to fix Denial of Service (DoS)? There is no fixed version for | [0,) |
gradio is a Python library for easily interacting with trained machine learning models Affected versions of this package are vulnerable to Undefined Behavior for Input to API via the How to fix Undefined Behavior for Input to API? There is no fixed version for | [4.0.0,) |
gradio is a Python library for easily interacting with trained machine learning models Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) through the How to fix Regular Expression Denial of Service (ReDoS)? There is no fixed version for | [4.38.0,) |
gradio is a Python library for easily interacting with trained machine learning models Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the How to fix Arbitrary File Write via Archive Extraction (Zip Slip)? There is no fixed version for | [4.0.0,) |
gradio is a Python library for easily interacting with trained machine learning models Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to no restrictions on the URL, in the How to fix Server-side Request Forgery (SSRF)? There is no fixed version for | [0,) |
gradio is a Python library for easily interacting with trained machine learning models Affected versions of this package are vulnerable to Arbitrary Code Injection due to improper check of the input, when users generate Note: This vulnerability is disputed by the maintainer because the report is about a user attacking himself. How to fix Arbitrary Code Injection? There is no fixed version for | [0,) |
gradio is a Python library for easily interacting with trained machine learning models Affected versions of this package are vulnerable to Open Redirect via the How to fix Open Redirect? There is no fixed version for | [0,) |