CVE-2026-48484 pyLoad 内存耗尽拒绝服务漏洞
影响攻击者可通过上传超大文件耗尽服务器内存,导致进程终止
pyLoad 是一款用 Python 编写的免费开源下载管理器。在其 API 的 rpc 函数处理 multipart/form-data 上传时,会先将整个上传文件读入内存,且未设置大小限制。攻击者上传超大文件即可耗尽服务器可用内存,造成进程被终止。
影响范围
pyLoad 0.5.0b3.dev101 之前的版本;0.5.0b3.dev101 已包含修复补丁。
漏洞详情
漏洞类型为不受限制的资源分配导致的拒绝服务(内存耗尽)。成因是 api_blueprint.py 中的 rpc 函数在处理 multipart/form-data 上传时,使用 file.read() 将整个文件内容一次性读入内存,且在读取前未设置任何大小限制。攻击者只需向该 API 上传一个超大文件,即可消耗服务器全部可用内存,导致进程被系统终止。
利用条件与风险
利用前提是攻击者能够访问并调用该 rpc API 上传接口,无需认证信息即可触发(视部署配置而定)。实战中可造成服务不可用,属于拒绝服务风险,CVSS 6.5 为中危。
修复建议
官方已在 0.5.0b3.dev101 版本中修复,建议升级至该版本或更高版本。临时缓解措施包括在反向代理或网关层限制上传请求体大小,并限制 API 接口的访问权限。
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server’s available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.