CVE-2024-10624
Description
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the gr.Datetime component. The affected version is git commit 98cbcae. The vulnerability arises from the use of a regular expression ^(?:\s*now\s*(?:-\s*(\d+)\s*([dmhs]))?)?\s*$ to process user input. In Python's default regex engine, this regular expression can take polynomial time to match certain crafted inputs. An attacker can exploit this by sending a crafted HTTP request, causing the gradio process to consume 100% CPU and potentially leading to a Denial of Service (DoS) condition on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gradioPyPI | >= 4.38.0, <= 5.0.0-beta.2 | — |
Affected products
3- cpe:2.3:a:gradio_project:gradio:2024-09-18:*:*:*:*:python:*:*
- Range: unspecified
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/e8d0b248-8feb-4c23-9ef9-be4d1e868374nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-rvgh-pr46-x7ggghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-10624ghsaADVISORY
- github.com/gradio-app/gradio/blob/98cbcaef827de7267462ccba180c7b2ffb1e825d/gradio/components/datetime.pyghsaWEB
News mentions
0No linked articles in our index yet.