Impact
The vulnerability arises because the API endpoint accepts multipart/form-data uploads without enforcing a size limit and reads the entire file into memory. A malicious actor can submit a very large file, causing the server to exhaust its RAM and terminate the pyLoad process, resulting in a denial of service. This is an unchecked input size flaw that leads to resource exhaustion.
Affected Systems
The issue affects pyLoad for versions older than 0.5.0b3.dev101, including all releases prior to that development build. Users running the open‑source download manager on any environment where the RPC API is exposed are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity; the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Nevertheless, the attack can be carried out by sending a large file to the RPC endpoint, making it a straightforward denial‑of‑service attack that requires no special privileges.
OpenCVE Enrichment
Github GHSA