PT-2026-108984 · Pyload · Pyload
CVE-2026-48484
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
pyLoad versions prior to 0.5.0b3.dev101
Description
The
rpc function in api blueprint.py handles multipart/form-data uploads by reading the entire content of the uploaded file into memory using file.read() before sending the data to the underlying function. Because no size limit is enforced during this process, uploading a large file can exhaust the server's available memory, leading to process termination by the operating system's Out-Of-Memory (OOM) killer or causing the system to become unresponsive due to swap thrashing. This results in a Denial of Service (DoS) and interrupts all active downloads or tasks.Recommendations
Update to version 0.5.0b3.dev101.
Enforce a maximum size for uploaded files in the web server configuration, such as using the
client max body size directive in Nginx.Fix
Resource Exhaustion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pyload