Junglewise Threat Intelligence

CVE-2026-59806: Gradio open redirect and SSRF in file_fetch function

CVE-2026-59806 · Severity: high · CVSS 7.4 · Published 2026-07-08

Technologies: Gradio.

Executive brief

Gradio, a popular library for building machine learning web interfaces, contains a security flaw in how it handles file requests. An attacker can use this to trick users into visiting malicious websites or, more seriously, force the system to leak sensitive cloud credentials (such as AWS IAM roles) by targeting internal metadata services. This could lead to unauthorized access to cloud infrastructure and sensitive data.

Technical details

An open redirect and client-side SSRF vulnerability exists in Gradio's file-serving logic. The `file_fetch()` function in the `/gradio_api/file=` endpoint (and its alias `/gradio_api/file/`) accepts unvalidated HTTP/HTTPS URLs and returns a 302 redirect. Because the `gradio_client` library follows redirects by default, an attacker can craft a malicious `FileData` response to perform SSRF against internal endpoints, such as the AWS EC2 metadata service (169.254.169.254), to exfiltrate IAM role credentials. The vulnerability is fixed in version 6.20.0 by implementing an SSRF-safe streaming proxy using `safehttpx` that validates IP addresses and prevents DNS rebinding.

Affected products

  • Gradio Gradio < 6.20.0

Timeline

  • 2026-06-03: disclosed: Vulnerability reported to vendor via email
  • 2026-07-06: patched: Fix committed to main branch
  • 2026-07-07: advisory: Release 6.20.0 published
  • 2026-07-08: disclosed: CVE-2026-59806 published

References