LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-28416

CVE-2026-28416 - Vulnerability Analysis

HighCVSS: 8.2

Last Updated: March 2, 2026

Gradio - Server-Side Request Forgery

Published: February 27, 2026Updated: March 2, 2026Remote Exploitable

Overview

Gradio < 6.6.0 contains a server-side request forgery caused by trusting malicious proxy_url in gr.load() config, letting attackers make arbitrary HTTP requests from victim servers, exploit requires victim to load attacker-controlled Space.

Severity & Score

Severity: High
CVSS Score: 8.2
EPSS Score: 3.0%(Probability of exploitation in next 30 days)

Impact

Attackers can make arbitrary HTTP requests from victim servers, accessing internal services and private networks.

Mitigation

Update to version 6.6.0 or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Feb 28, 2026

🟠 CVE-2026-28416 - High (8.2) Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP requests from a victim's server by hosting a mal... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-28416/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-28416
Severity
High
CVSS Score
8.2
Type
server_side_request_forgery
Status
unconfirmed
EPSS
3.0%
Social Posts
1

CWE

  • CWE-918

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

EPSS Score

3.0%Probability of exploitation in the next 30 days