CVE-2026-48484
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.
| CWE | CWE-20 CWE-400 |
| Vendor | pyload |
| Product | pyload |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for pyload pyload
Be the first to know when new medium vulnerabilities affecting pyload pyload are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
pyload / pyload
< 0.5.0b3.dev101
References
github.com: https://github.com/pyload/pyload/security/advisories/GHSA-vq8p-m3wm-gv5f github.com: https://github.com/pyload/pyload/commit/461cd66f30fa9e96453fb4d8c5c47467e452363c github.com: https://github.com/pyload/pyload/blob/8e447958b8a66c5899775e725a8b90bce6643004/src/pyload/webui/app/blueprints/api_blueprint.py#L73