Impact
The vulnerability stems from EventManager not clearing inactive client objects when the authenticated getEvents API endpoint receives unique UUIDs. Each request with a new UUID creates a Client instance that is appended to an internal clients list, and because the get_events method does not call the available clean routine, the list grows without bound. An attacker with authenticated access can repeatedly submit distinct UUIDs, causing retained client objects and increasing process memory until the system runs an operating‑system out‑of‑memory termination of pyLoad or cause host‑wide instability and denial of service for legitimate users. The issue is fixed in version 0.5.0b3.dev101.
Affected Systems
This flaw affects pyLoad, a Python‑based open‑source download manager, in all releases prior to 0.5.0b3.dev101.‑side code in src/pyload/core/managers/event_manager.py; any installation potentially exposing the authenticated getEvents API is vulnerable.
Risk and Exploitability
The CVSS score assigned to this issue is 6.5, indicating a moderate risk level. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated access to the getEvents API, and the path to exploitation involves sending a high volume of requests with unique UUID payloads. Since each request expands an internal list, the memory consumption climbs linearly with the number of requests, making the attack highly scalable if multiple malicious users coordinate. The resultant denial of service can affect the single pyLoad instance or the host machine if the process is killed, making the impact potentially system‑wide.
OpenCVE Enrichment
Github GHSA