Improper Validation of Specified Quantity in Input Affecting nicegui package, versions [,3.9.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.6% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-NICEGUI-15701842
  • published20 Mar 2026
  • disclosed19 Mar 2026
  • creditKhaliun-sw1, SeongHun Pak

Introduced: 19 Mar 2026

CVE-2026-33332  (opens in a new tab)
CWE-1284  (opens in a new tab)

How to fix?

Upgrade nicegui to version 3.9.0 or higher.

Overview

nicegui is a Create web-based user interfaces with Python. The nice way.

Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input in the chunk_size parameter in app.add_media_file() and app.add_media_files() media routes. An attacker can cause excessive memory consumption and degrade server performance by sending crafted requests with large or unvalidated values, leading the server to load entire files into memory instead of streaming them in chunks. This can be amplified with concurrent requests to large media files.

CVSS Base Scores

version 4.0
version 3.1