---
id: CVE-2026-48484
title: pyLoad is a free and open-source download manager written in Python
summary: >-
  pyLoad is a free and open-source download manager written in Python. Prior to
  0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles
  `multipart/form-data` uploads by reading the whole content of the uploaded
  file into memor…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
  - CWE-400
vendor: pyload-ng
product: pyload-ng
affected:
  - pyload-ng < 0.5.0b3.dev101
patched:
  - pyload-ng 0.5.0b3.dev101
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T17:16:47.663'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48484'
references:
  - url: >-
      https://github.com/pyload/pyload/blob/8e447958b8a66c5899775e725a8b90bce6643004/src/pyload/webui/app/blueprints/api_blueprint.py#L73
    label: security-advisories@github.com
  - url: >-
      https://github.com/pyload/pyload/commit/461cd66f30fa9e96453fb4d8c5c47467e452363c
    label: security-advisories@github.com
  - url: 'https://github.com/pyload/pyload/security/advisories/GHSA-vq8p-m3wm-gv5f'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-vq8p-m3wm-gv5f'
tags:
  - nvd
  - ghsa
  - pip
aliases:
  - GHSA-vq8p-m3wm-gv5f
ecosystem: pip
ingestedAt: '2026-10-09T17:04:42.815Z'
---

## Overview

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-48484)

Affected packages:

- `pyload-ng < 0.5.0b3.dev101`

Patched in:

- `pyload-ng 0.5.0b3.dev101`

Source: https://github.com/advisories/GHSA-vq8p-m3wm-gv5f
