CVE-2026-48484Medium· 6.5▾ SunlitpyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memor…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API rpc function in api_blueprint.py handles multipart/form-data uploads by reading the whole content of the uploaded file into memory with file.read(). This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
pyload-ng < 0.5.0b3.dev101Patched in:
pyload-ng 0.5.0b3.dev101Connected by shared product, vendor, weakness, or advisory.
GHSA-p3pr-8f3m-4qp8Medium· 6.4pyLoad WindowsPhoneNotify addon: non-admin SETTINGS user triggers SSRF via unguarded http.client notification host
GHSA-fr26-jjhm-638cHighpyLoad: Tar extraction creates device nodes and FIFOs (member types not filtered; tarfile extractall without filter=)
GHSA-jq7h-wrvp-3rgxHigh· 7.5pyLoad: Privilege revocation and password change through the REST API do not invalidate the user's session
GHSA-889w-m37p-88m5High· 7.5pyLoad: Api.set_user_permission never invalidates the target's session
GHSA-68w4-83fh-f2w8High· 8.1pyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password
GHSA-9q47-3cm2-2rp8MediumpyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header