Vulnerability GHSA-vq8p-m3wm-gv5f
Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 hours ago
October 09, 2026 at 04:26 PM UTC
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination
0.5.0a5.dev528 - 0.5.0b3.dev100
0.5.0a5.dev528 - 0.5.0b3.dev100
Summary
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination
Details
Description:
The API rpc function in api_blueprint.py handles multipart/form-data uploads by reading the whole content of the uploaded file into memory with file.read(). This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination.
VulnerableCode & Path:
Steps to Reproduce:
- Log in to pyLoad (or use an API key, here i used api to communicate).
- Prepare a large file (e.g., 10GB) .
truncate -s 10G large_file.bin
- Send a multipart request to an API function that accepts a file, such as
check_online_status_container:
curl -X POST "http://localhost:8000/api/rpc" \
-H "X-API-Key: YOUR_API_KEY" \
-F "func=check_online_status_container" \
-F "container=@large_file.bin"
- Monitor the server's memory usage. The process will attempt to allocate memory for the entire file and last the process will be killed by the kernel.
Impact
- Denial of Service (DoS): The pyLoad process will be killed by the Operating System's Out-Of-Memory (OOM) killer, or the entire system may become unresponsive due to swap thrashing or memory exhaustion.
- Service Instability: Any active downloads or tasks will be interrupted.
Mitigations
- Implement File Size Limits: Enforce a maximum size for uploaded files in the web server configuration (e.g., Nginx
client_max_body_size).
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 hours ago
pyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password
0.5.0b3.dev13 - 0.5.0b3.dev101 GHSA-68w4-83fh-f2w8
0.5.0b3.dev13 - 0.5.0b3.dev101 GHSA-68w4-83fh-f2w8
Medium Risk
3 hours ago
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header
0.5.0b3.dev101 GHSA-9q47-3cm2-2rp8
0.5.0b3.dev101 GHSA-9q47-3cm2-2rp8
High Risk
3 hours ago
pyLoad: Privilege revocation and password change through the REST API do not invalidate the user's session
0.5.0a5.dev528 - 0.5.0b3.dev101 GHSA-jq7h-wrvp-3rgx
0.5.0a5.dev528 - 0.5.0b3.dev101 GHSA-jq7h-wrvp-3rgx
High Risk
3 hours ago
pyLoad: Api.set_user_permission never invalidates the target's session
0.5.0b3.dev98 - 0.5.0b3.dev101 GHSA-889w-m37p-88m5
0.5.0b3.dev98 - 0.5.0b3.dev101 GHSA-889w-m37p-88m5
Medium Risk
3 hours ago
pyLoad WindowsPhoneNotify addon: non-admin SETTINGS user triggers SSRF via unguarded http.client notification host
0.5.0a5.dev528 - 0.5.0b3.dev101 GHSA-p3pr-8f3m-4qp8
0.5.0a5.dev528 - 0.5.0b3.dev101 GHSA-p3pr-8f3m-4qp8
Impacted packages
Timeline
Published
3 hours ago
October 09, 2026 at 04:26 PM UTC
Fixed (0.5.0b3.dev101)
3 months ago
July 09, 2026 at 04:55 PM UTC
Last Modified
3 hours ago
October 09, 2026 at 04:30 PM UTC