Upload of the file dash_uploader/httprequesthandler.py. Such manipulation of the argument max_file_size leads to unrestricted upload.This vulnerability is listed as CVE-2026-38361. The attack may be performed from remote. There is no available exploit.