In chunked mode, ApiUpload allows a client to send data past the stated filesize. If the filesize parameter is kept suitably small, I believe a badly coded or malicious client could conceivably upload indefinitely.
patches:
affected versions:
type: DoS
CVE: CVE-2015-8001