Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-vq8p-m3wm-gv5f
Description:
The API rpc function in api_blueprint.py handles multipart/form-data uploads by reading the whole content of the uploaded file into memory with file.read(). This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination.
VulnerableCode & Path:
https://github.com/pyload/pyload/blob/8e447958b8a66c5899775e725a8b90bce6643004/src/pyload/webui/app/blueprints/api_blueprint.py#L73
Steps to Reproduce:
- Log in to pyLoad (or use an API key, here i used api to communicate).
- Prepare a large file (e.g., 10GB) .
truncate -s 10G large_file.bin
- Send a multipart request to an API function that accepts a file, such as
check_online_status_container:
curl -X POST "http://localhost:8000/api/rpc" \
-H "X-API-Key: YOUR_API_KEY" \
-F "func=check_online_status_container" \
-F "container=@large_file.bin"
- Monitor the server's memory usage. The process will attempt to allocate memory for the entire file and last the process will be killed by the kernel. <img width="1902" height="610" alt="dos-process-kill-poc" src="https://github.com/user-attachments/assets/2b9bfd0f-5b9f-48dd-983f-f97dfcc358cc" />
Impact
- Denial of Service (DoS): The pyLoad process will be killed by the Operating System's Out-Of-Memory (OOM) killer, or the entire system may become unresponsive due to swap thrashing or memory exhaustion.
- Service Instability: Any active downloads or tasks will be interrupted.
Mitigations
- Implement File Size Limits: Enforce a maximum size for uploaded files in the web server configuration (e.g., Nginx
client_max_body_size).
Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.
Drag and drop some file here, or click to select
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker needs basic access or low-level privileges. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a high impact on the availability of the system.
Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.
Probability that this vulnerability will be exploited in the wild within the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
- CVE-2026-48484Alias
- EUVD-2026-95910Alias
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard