CVE-2026-28416Disclosure(gradio_project / gradio)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gradio_project gradio systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP requests from a victim's server by hosting a malicious Gradio Space. When a victim application uses `gr.load()` to load an attacker-controlled Space, the malicious `proxy_url` from the config is trusted and added to the allowlist, enabling the attacker to access internal services, cloud metadata endpoints, and private networks through the victim's infrastructure. Version 6.6.0 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gradio

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-28); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
gradio

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-27: 1Mentions · 2026-02-28: 2Mentions · 2026-03-01: 1Mentions · 2026-03-04: 1Patch / Workaround · 2026-03-01: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-01: 1Technical Details · 2026-03-04: 102-2702-2803-0103-04
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-271
Disclosure1
2026-02-282
Disclosure2
2026-03-011
Patch1
2026-03-041
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28416 (CVSS:8.2, HIGH) is Undergoing Analysis. Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Fo..https://nvd.nist.gov/vuln/detail/CVE-2026-28416 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-28416 is a high‑severity SSRF vulnerability in Gradio versions before 6.6.0, currently under analysis with no PoC or exploit details disclosed.

    0000035
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Gradio` instances are vulnerable to SSRF (CVE-2026-28416) via `proxy_url` injection. Update `gradio` to the patched version to mitigate risks. #Gradio #SSRF #infosec https://www.pulsepatch.io/posts/cve-2026-28416-gradio-ssrf-vulnerability

    Post summary

    Gradio instances are vulnerable to SSRF via proxy_url injection (CVE‑2026‑28416). Updating to the patched version mitigates the risk.

    0000055
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28416 Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an… https://www.cve.org/CVERecord?id=CVE-2026-28416

    Post summary

    The text announces a Server‑Side Request Forgery vulnerability in Gradio prior to version 6.6.0, providing the vulnerability type but no PoC, exploit, or patch details.

    00000116
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28416 Server-Side Request Forgery in Gradio Python Package Before Versi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28416 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-28416, an SSRF vulnerability in the Gradio Python Package, and provides a link to a vulnerability details page, but offers no proof of concept, exploit code, active exploitation evidence, or patch information.

    0000063
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28416 - High Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitra... https://www.thehackerwire.com/vulnerability/CVE-2026-28416/ https://t.co/zwnk09LTtm

    Post summary

    A high‑severity SSRF vulnerability (CVE‑2026‑28416) in Gradio versions before 6.6.0 is disclosed, allowing attackers to make arbitrary requests; no PoC, exploit, patch, or active exploitation is mentioned.

    0000060
    119 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgradio_projectgradio-python-

Explore more