PT-2026-108984 · Pyload · Pyload

CVE-2026-48484

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions pyLoad versions prior to 0.5.0b3.dev101
Description The rpc function in api blueprint.py handles multipart/form-data uploads by reading the entire content of the uploaded file into memory using file.read() before sending the data to the underlying function. Because no size limit is enforced during this process, uploading a large file can exhaust the server's available memory, leading to process termination by the operating system's Out-Of-Memory (OOM) killer or causing the system to become unresponsive due to swap thrashing. This results in a Denial of Service (DoS) and interrupts all active downloads or tasks.
Recommendations Update to version 0.5.0b3.dev101. Enforce a maximum size for uploaded files in the web server configuration, such as using the client max body size directive in Nginx.

Fix

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48484
GHSA-VQ8P-M3WM-GV5F

Affected Products

Pyload