← Vulnerability feed

Vulnerability record · CVE-2026-33332 · published 24 March 2026

CVE-2026-33332: Zauberzeug nicegui improper input validation vulnerability

Zauberzeug · Nicegui

NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept a user-controlled query parameter that influences how files are read during streaming. The parameter is passed to the range-response implementation without validation, allowing an attacker to bypass chunked streaming and force the server to load entire files into memory at once. With large media files and concurrent requests, this can lead to excessive memory consumption, degraded performance, or denial of service. This issue has been patched in version 3.9.0.

6.9 CVSS 4.0 Medium EPSS 0.69% · top 49.1% CWE-20 · Improper input validationCWE-770 · Allocation without limits
6.9CVSS 4.0 base score
0.69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept a user-controlled query parameter that influences how files are read during streaming. The parameter is passed to the range-response implementation without validation, allowing an attacker to bypass chunked streaming and force the server to load entire files into memory at once. With large media files and concurrent requests, this can lead to excessive memory consumption, degraded performance, or denial of service. This issue has been patched in version 3.9.0.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33332 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-39844Zauberzeug nicegui path traversal vulnerabilityNiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can …EPSS 0.49%7.5CVE-2026-25732Zauberzeug nicegui path traversal vulnerabilityNiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitiza…EPSS 3.0%7.5CVE-2025-66645Zauberzeug nicegui path traversal vulnerabilityNiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, wh…EPSS 1.1%6.1CVE-2026-27156Zauberzeug nicegui cross-site scripting vulnerabilityNiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`Element.run_metho…EPSS 0.27%6.1CVE-2026-25516Zauberzeug nicegui cross-site scripting vulnerabilityNiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown content to HTML, which is then ren…EPSS 0.29%6.1CVE-2026-21871Zauberzeug nicegui cross-site scripting vulnerabilityNiceGUI is a Python-based UI framework. From versions 2.13.0 to 3.4.1, there is a XSS risk in NiceGUI when developers pass attacker-controlled string…EPSS 0.28%6.1CVE-2026-21872Zauberzeug nicegui cross-site scripting vulnerabilityNiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the click event listener used by ui.sub_pages, com…EPSS 0.27%6.1CVE-2026-21873Zauberzeug nicegui cross-site scripting vulnerabilityNiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the pushstate event listener used by ui.sub_pages …EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2026-33332), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.