Medium severity6.5GHSA Advisory· Published Oct 9, 2026· Updated Oct 9, 2026
CVE-2026-48484
CVE-2026-48484
Description
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API rpc function in api_blueprint.py handles multipart/form-data uploads by reading the whole content of the uploaded file into memory with file.read(). This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-vq8p-m3wm-gv5fghsaADVISORY
- github.com/pyload/pyload/blob/8e447958b8a66c5899775e725a8b90bce6643004/src/pyload/webui/app/blueprints/api_blueprint.pynvd
- github.com/pyload/pyload/commit/461cd66f30fa9e96453fb4d8c5c47467e452363cnvd
- github.com/pyload/pyload/security/advisories/GHSA-vq8p-m3wm-gv5fnvd
News mentions
0No linked articles in our index yet.