
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48484 is a Denial of Service (DoS) vulnerability in pyLoad, a free and open-source download manager written in Python, caused by a lack of input size validation during file uploads. The rpc function in api_blueprint.py reads the entire content of a multipart/form-data uploaded file into memory using file.read() without enforcing any size limit, allowing an authenticated attacker to exhaust server memory and terminate the process. All versions of pyload-ng prior to 0.5.0b3.dev101 are affected. The vulnerability was published on October 8–9, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory).
The root cause is improper input validation (CWE-20) combined with uncontrolled resource consumption (CWE-400). In src/pyload/webui/app/blueprints/api_blueprint.py at line 73, when the request MIME type is multipart/form-data, the handler calls file.read() unconditionally — loading the entire uploaded file into memory before passing it to the underlying API function — with no MAX_CONTENT_LENGTH or equivalent size cap configured (pyload source). An attacker must be authenticated (via session or API key) and can target any API endpoint that accepts file uploads, such as check_online_status_container, by sending a crafted multipart/form-data POST request to /api/rpc with an arbitrarily large file (Github Advisory). The fix adds MAX_CONTENT_LENGTH = 16 * 1024 * 1024 (16 MB) to the Flask application configuration (pyload commit).
Successful exploitation causes the pyLoad process to be terminated by the operating system's Out-Of-Memory (OOM) killer, or renders the entire system unresponsive due to swap thrashing or memory exhaustion. All active downloads and tasks managed by pyLoad are interrupted upon process termination. There is no confidentiality or integrity impact; the vulnerability is limited to a high availability impact on the affected pyLoad instance (Github Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory). Exploitation requires low-privilege authenticated access, which somewhat limits the attack surface, though API keys may be obtainable through credential theft or weak configurations.
0.5.0b3.dev101 and that the /api/rpc endpoint is accessible over the network.truncate -s 10G large_file.bin.multipart/form-data POST request to the /api/rpc endpoint with the large file attached, targeting a file-accepting function:curl -X POST "http://<target>:8000/api/rpc" \
-H "X-API-Key: YOUR_API_KEY" \
-F "func=check_online_status_container" \
-F "container=@large_file.bin"file.read(), exhausting available RAM and triggering the OOM killer, which terminates the pyLoad process and disrupts all active downloads (Github Advisory)./api/rpc with Content-Type: multipart/form-data; sustained high-bandwidth inbound traffic to the pyLoad web port (default 8000)./api/rpc with very large Content-Length values; repeated requests from the same source IP targeting file-upload API functions./var/log/syslog or dmesg referencing the pyLoad process (e.g., Out of memory: Kill process <pid> (python)); unexpected process termination of pyLoad.Upgrade pyload-ng to version 0.5.0b3.dev101 or later, which introduces a MAX_CONTENT_LENGTH = 16 MB limit in the Flask application configuration, preventing unbounded file reads (pyload commit). As an interim workaround, enforce upload size limits at the reverse proxy or web server layer (e.g., set client_max_body_size in Nginx or LimitRequestBody in Apache) to reject oversized requests before they reach the pyLoad application (Github Advisory). Additionally, restrict API access to trusted networks and rotate or revoke API keys if unauthorized access is suspected.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."