PT-2026-26484 · Nicegui · Nicegui

Aest3Ra

+1

·

Published

2026-03-19

·

Updated

2026-03-24

·

CVE-2026-33332

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NiceGUI versions prior to 3.9.0
Description NiceGUI’s app.add media file() and app.add media files() functions are susceptible to a flaw where a user-controlled query parameter, passed to the range-response implementation without validation, can bypass chunked streaming. This allows an attacker to force the server to load entire files into memory. With large media files and concurrent requests, this can lead to excessive memory consumption, degraded performance, or denial of service. The vulnerable functions are used for serving media content. The parameter is passed to the range-response implementation.
Recommendations Upgrade to NiceGUI version 3.9.0 or later. As a workaround, restrict access to media endpoints. As a workaround, strip unexpected query parameters at a reverse proxy layer.

Exploit

Fix

Allocation of Resources Without Limits

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-33332
GHSA-W5G8-5849-VJ76

Affected Products

Nicegui