CVE-2026-48484: Pyload
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.
Affected products
- Pyload Pyload: before 0.5.0b3.dev101 (fixed in 0.5.0b3.dev101)
Published 2026-10-09. Last modified 2026-10-09.