Description
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.
Published: 2026-10-09
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability arises because the API endpoint accepts multipart/form-data uploads without enforcing a size limit and reads the entire file into memory. A malicious actor can submit a very large file, causing the server to exhaust its RAM and terminate the pyLoad process, resulting in a denial of service. This is an unchecked input size flaw that leads to resource exhaustion.

Affected Systems

The issue affects pyLoad for versions older than 0.5.0b3.dev101, including all releases prior to that development build. Users running the open‑source download manager on any environment where the RPC API is exposed are at risk.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity; the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Nevertheless, the attack can be carried out by sending a large file to the RPC endpoint, making it a straightforward denial‑of‑service attack that requires no special privileges.

Generated by OpenCVE AI on October 9, 2026 at 17:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch to version 0.5.0b3.dev101 or later.
  • If upgrading is not immediately possible, configure the application or web server to reject large uploads before the API reads them by enforcing a maximum file size limit.
  • Monitor memory usage and consider imposing resource limits or container constraints to mitigate a potential exhaustion attack.

Generated by OpenCVE AI on October 9, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vq8p-m3wm-gv5f pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination
History

Fri, 09 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Pyload
Pyload pyload
Vendors & Products Pyload
Pyload pyload

Fri, 09 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.
Title pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination
Weaknesses CWE-20
CWE-400
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T16:26:37.728Z

Reserved: 2026-05-21T15:33:08.291Z

Link: CVE-2026-48484

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T17:16:47.487

Modified: 2026-10-09T17:16:47.663

Link: CVE-2026-48484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T17:30:08Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-400

    Uncontrolled Resource Consumption