Memory Exhaustion Vulnerability in pyLoad Download Manager
CVE-2026-48484
6.5MEDIUM
What is CVE-2026-48484?
The pyLoad download manager has a vulnerability that occurs due to an improper handling of file uploads within the API's rpc function. When users upload files via multipart/form-data, the entire content is read into memory without a size restriction. This can lead to excessive memory consumption, potentially exhausting server resources and causing process termination. The issue has been addressed in version 0.5.0b3.dev101, which includes a crucial patch to limit the size of uploaded files, preventing such memory exploitation.
Affected Version(s)
pyload < 0.5.0b3.dev101
