Description
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid submitted to the authenticated getEvents API endpoint, but get_events does not invoke the available clean method to remove inactive clients. An authenticated user can repeatedly submit unique UUID values, causing retained client objects and process memory to grow without bound even after requests stop. The resulting memory exhaustion can trigger an operating-system out-of-memory termination of pyLoad or host-wide instability and denial of service. This issue is fixed in version 0.5.0b3.dev101.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service from unbounded memory growth
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from EventManager not clearing inactive client objects when the authenticated getEvents API endpoint receives unique UUIDs. Each request with a new UUID creates a Client instance that is appended to an internal clients list, and because the get_events method does not call the available clean routine, the list grows without bound. An attacker with authenticated access can repeatedly submit distinct UUIDs, causing retained client objects and increasing process memory until the system runs an operating‑system out‑of‑memory termination of pyLoad or cause host‑wide instability and denial of service for legitimate users. The issue is fixed in version 0.5.0b3.dev101.

Affected Systems

This flaw affects pyLoad, a Python‑based open‑source download manager, in all releases prior to 0.5.0b3.dev101.‑side code in src/pyload/core/managers/event_manager.py; any installation potentially exposing the authenticated getEvents API is vulnerable.

Risk and Exploitability

The CVSS score assigned to this issue is 6.5, indicating a moderate risk level. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated access to the getEvents API, and the path to exploitation involves sending a high volume of requests with unique UUID payloads. Since each request expands an internal list, the memory consumption climbs linearly with the number of requests, making the attack highly scalable if multiple malicious users coordinate. The resultant denial of service can affect the single pyLoad instance or the host machine if the process is killed, making the impact potentially system‑wide.

Generated by OpenCVE AI on September 17, 2026 at 15:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pyLoad to version 0.5.0b3.dev101 or later, which includes the necessary cleanup logic.
  • If upgrading immediately is not an option, temporarily mitigate by implementing rate‑limiting on the getEvents endpoint or by rejecting requests with previously seen UUIDs beyond a configurable threshold.
  • trusted IP ranges or requiring stronger authentication to limit the attack surface.

Generated by OpenCVE AI on September 17, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c2f9-4mc8-j656 pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager
History

Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Pyload
Pyload pyload
Vendors & Products Pyload
Pyload pyload

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid submitted to the authenticated getEvents API endpoint, but get_events does not invoke the available clean method to remove inactive clients. An authenticated user can repeatedly submit unique UUID values, causing retained client objects and process memory to grow without bound even after requests stop. The resulting memory exhaustion can trigger an operating-system out-of-memory termination of pyLoad or host-wide instability and denial of service. This issue is fixed in version 0.5.0b3.dev101.
Title pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager
Weaknesses CWE-400
CWE-401
CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:59:08.509Z

Reserved: 2026-05-26T23:26:07.975Z

Link: CVE-2026-48987

cve-icon Vulnrichment

Updated: 2026-09-15T14:55:23.876Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:16.397

Modified: 2026-09-16T13:42:49.090

Link: CVE-2026-48987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T15:45:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-770

    Allocation of Resources Without Limits or Throttling