{"id":"CVE-2026-48484","title":"pyLoad is a free and open-source download manager written in Python","summary":"pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memor…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20","CWE-400"],"vendor":"pyload-ng","product":"pyload-ng","affected":["pyload-ng < 0.5.0b3.dev101"],"patched":["pyload-ng 0.5.0b3.dev101"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T17:16:47.663","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48484","references":[{"url":"https://github.com/pyload/pyload/blob/8e447958b8a66c5899775e725a8b90bce6643004/src/pyload/webui/app/blueprints/api_blueprint.py#L73","label":"security-advisories@github.com"},{"url":"https://github.com/pyload/pyload/commit/461cd66f30fa9e96453fb4d8c5c47467e452363c","label":"security-advisories@github.com"},{"url":"https://github.com/pyload/pyload/security/advisories/GHSA-vq8p-m3wm-gv5f","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-vq8p-m3wm-gv5f"}],"tags":["nvd","ghsa","pip"],"aliases":["GHSA-vq8p-m3wm-gv5f"],"ecosystem":"pip","ingestedAt":"2026-10-09T17:04:42.815Z","slug":"CVE-2026-48484","body":"## Overview\n\npyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-48484)\n\nAffected packages:\n\n- `pyload-ng < 0.5.0b3.dev101`\n\nPatched in:\n\n- `pyload-ng 0.5.0b3.dev101`\n\nSource: https://github.com/advisories/GHSA-vq8p-m3wm-gv5f","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}