
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was discovered in the dataframe component of gradio-app/gradio (version git 98cbcae) that allows for a zip bomb attack. The vulnerability was disclosed on March 20, 2025, and affects the component's handling of input values through pd.read_csv functionality (NVD).
The vulnerability stems from the dataframe component's use of pd.read_csv to process input values, which can accept compressed files. The severity of this vulnerability has been rated as HIGH with a CVSS v3.0 base score of 7.5 (Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The vulnerability is classified under CWE-475 (Undefined Behavior for Input to API) (Huntr).
When exploited, this vulnerability can lead to a server crash and cause a denial of service condition. The attack can be initiated by uploading a maliciously crafted zip bomb, which can potentially consume excessive server resources (NVD).
The vulnerability can be exploited remotely by an attacker without requiring authentication or user interaction. The attack vector is network-accessible, and the complexity of exploitation is considered low (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."