CVE-2026-33332·Python vulnerability
NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept a user-controlled query parameter that influences how files are read during streaming. The parameter is passed to the range-response implementation without validation, allowing an attacker to bypass chunked streaming and force the server to load entire files into memory at once. With large media files and concurrent requests, this can lead to excessive memory consumption, degraded performance, or denial of service. This issue has been patched in version 3.9.0.
- Severity
- high
- Software
- Python
- Fixed in
- 3.9.0
- Published
- 2026-03-24
Affected versions
Until: 3.9.0
Fixed in: 3.9.0
How to fix this CVE
Update NiceGUI to version 3.9.0 or later to patch the media file streaming vulnerability. This fix validates query parameters passed to the range-response handler, preventing attackers from forcing full file loads into memory. If you use NiceGUI in production, prioritize this update to mitigate potential denial-of-service attacks via malicious range requests.
sudo dnf update python3-niceguiDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET /api/media/stream.*Range.*(?:bytes=|\d+-\d+|\*) followed by abnormal memory consumption or HTTP 416 Range Not Satisfiable responsesWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block or restrict HTTP Range header requests to media endpoints that use NiceGUI's add_media_file/add_media_files routes; implement query parameter validation on media route handlers to reject non-standard range specificationsHow to check if you are affected
- Check NiceGUI version: python3 -c "import nicegui; print(nicegui.__version__)"
- Identify media routes in your application: grep -r "add_media_file\|add_media_files" /path/to/your/app
- Monitor system memory and request logs for sudden spikes during media file requests: journalctl -u your_app -f | grep -i 'memory\|range'
- Verify the patched version is installed: python3 -c "import nicegui; assert nicegui.__version__ >= '3.9.0', 'Vulnerable version detected'"
FAQ
What is CVE-2026-33332?
CVE-2026-33332 is a memory exhaustion vulnerability in NiceGUI's media file streaming that allows attackers to bypass chunked transfer encoding by manipulating unvalidated query parameters, forcing entire files into memory and causing denial of service.
Is CVE-2026-33332 being actively exploited?
No, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available, though the attack method is straightforward for authenticated threat actors.
What versions of NiceGUI are affected by CVE-2026-33332?
All versions of NiceGUI prior to 3.9.0 are affected by this vulnerability.
How do I check if my server is vulnerable to CVE-2026-33332?
Run: python3 -c "import nicegui; print('Vulnerable' if nicegui.__version__ < '3.9.0' else 'Patched')" on your application server. If NiceGUI is not installed, this CVE does not apply to your environment.
Does Defensia detect CVE-2026-33332?
Yes — Defensia's CVE advisory scanner compares installed NiceGUI versions against the NVD database. If NiceGUI is detected on a monitored server, CVE-2026-33332 will appear in your dashboard with distribution-specific remediation commands.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-33332. Free for 1 server.
Get started free