A vulnerability labeled as problematic has been found in zauberzeug nicegui up to 3.8.x. This affects the function app.add_media_file/app.add_media_files of the component Query Parameter Handler. The manipulation results in denial of service.

This vulnerability is identified as CVE-2026-33332. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.