Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vq8p-m3wm-gv5f | pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination |
Fri, 09 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pyload
Pyload pyload |
|
| Vendors & Products |
Pyload
Pyload pyload |
Fri, 09 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch. | |
| Title | pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination | |
| Weaknesses | CWE-20 CWE-400 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T16:26:37.728Z
Reserved: 2026-05-21T15:33:08.291Z
Link: CVE-2026-48484
No data.
Status : Deferred
Published: 2026-10-09T17:16:47.487
Modified: 2026-10-09T17:16:47.663
Link: CVE-2026-48484
No data.
OpenCVE Enrichment
Updated: 2026-10-09T17:30:08Z

Github GHSA