GHSA-vq8p-m3wm-gv5f

Suggest an improvement
Source
https://github.com/advisories/GHSA-vq8p-m3wm-gv5f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-vq8p-m3wm-gv5f/GHSA-vq8p-m3wm-gv5f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vq8p-m3wm-gv5f
Aliases
  • CVE-2026-48484
Published
2026-10-09T16:26:53Z
Modified
2026-10-09T16:30:07Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination
Details

Description:

The API rpc function in api_blueprint.py handles multipart/form-data uploads by reading the whole content of the uploaded file into memory with file.read(). This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination.

VulnerableCode & Path:

https://github.com/pyload/pyload/blob/8e447958b8a66c5899775e725a8b90bce6643004/src/pyload/webui/app/blueprints/api_blueprint.py#L73

Steps to Reproduce:

  1. Log in to pyLoad (or use an API key, here i used api to communicate).
  2. Prepare a large file (e.g., 10GB) .
truncate -s 10G large_file.bin
  1. Send a multipart request to an API function that accepts a file, such as check_online_status_container:
curl -X POST "http://localhost:8000/api/rpc" \
     -H "X-API-Key: YOUR_API_KEY" \
     -F "func=check_online_status_container" \
     -F "container=@large_file.bin"
  1. Monitor the server's memory usage. The process will attempt to allocate memory for the entire file and last the process will be killed by the kernel. dos-process-kill-poc

Impact

  • Denial of Service (DoS): The pyLoad process will be killed by the Operating System's Out-Of-Memory (OOM) killer, or the entire system may become unresponsive due to swap thrashing or memory exhaustion.
  • Service Instability: Any active downloads or tasks will be interrupted.

Mitigations

  • Implement File Size Limits: Enforce a maximum size for uploaded files in the web server configuration (e.g., Nginx client_max_body_size).
Database specific
{
    "cwe_ids": [
        "CWE-20",
        "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-09T16:26:53Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

PyPI / pyload-ng

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.5.0b3.dev101

Affected versions

0.*
0.5.0a5.dev528
0.5.0a5.dev532
0.5.0a5.dev535
0.5.0a5.dev536
0.5.0a5.dev537
0.5.0a5.dev539
0.5.0a5.dev540
0.5.0a5.dev545
0.5.0a5.dev562
0.5.0a5.dev564
0.5.0a5.dev565
0.5.0a6.dev570
0.5.0a6.dev578
0.5.0a6.dev587
0.5.0a7.dev596
0.5.0a8.dev602
0.5.0a9.dev615
0.5.0a9.dev629
0.5.0a9.dev632
0.5.0a9.dev641
0.5.0a9.dev643
0.5.0a9.dev655
0.5.0a9.dev806
0.5.0b1.dev1
0.5.0b1.dev2
0.5.0b1.dev3
0.5.0b1.dev4
0.5.0b1.dev5
0.5.0b2.dev9
0.5.0b2.dev10
0.5.0b2.dev11
0.5.0b2.dev12
0.5.0b3.dev13
0.5.0b3.dev14
0.5.0b3.dev17
0.5.0b3.dev18
0.5.0b3.dev19
0.5.0b3.dev20
0.5.0b3.dev21
0.5.0b3.dev22
0.5.0b3.dev24
0.5.0b3.dev26
0.5.0b3.dev27
0.5.0b3.dev28
0.5.0b3.dev29
0.5.0b3.dev30
0.5.0b3.dev31
0.5.0b3.dev32
0.5.0b3.dev33
0.5.0b3.dev34
0.5.0b3.dev35
0.5.0b3.dev38
0.5.0b3.dev39
0.5.0b3.dev40
0.5.0b3.dev41
0.5.0b3.dev42
0.5.0b3.dev43
0.5.0b3.dev44
0.5.0b3.dev45
0.5.0b3.dev46
0.5.0b3.dev47
0.5.0b3.dev48
0.5.0b3.dev49
0.5.0b3.dev50
0.5.0b3.dev51
0.5.0b3.dev52
0.5.0b3.dev53
0.5.0b3.dev54
0.5.0b3.dev57
0.5.0b3.dev60
0.5.0b3.dev62
0.5.0b3.dev64
0.5.0b3.dev65
0.5.0b3.dev66
0.5.0b3.dev67
0.5.0b3.dev68
0.5.0b3.dev69
0.5.0b3.dev70
0.5.0b3.dev71
0.5.0b3.dev72
0.5.0b3.dev73
0.5.0b3.dev74
0.5.0b3.dev75
0.5.0b3.dev76
0.5.0b3.dev77
0.5.0b3.dev78
0.5.0b3.dev79
0.5.0b3.dev80
0.5.0b3.dev81
0.5.0b3.dev82
0.5.0b3.dev85
0.5.0b3.dev87
0.5.0b3.dev88
0.5.0b3.dev89
0.5.0b3.dev90
0.5.0b3.dev91
0.5.0b3.dev92
0.5.0b3.dev93
0.5.0b3.dev94
0.5.0b3.dev95
0.5.0b3.dev96
0.5.0b3.dev97
0.5.0b3.dev98
0.5.0b3.dev99
0.5.0b3.dev100

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-vq8p-m3wm-gv5f/GHSA-vq8p-m3wm-gv5f.json"