CVE 6.5 MEDIUM

pyload-ng: Improper Authentication and Origin Validation Error_CVE-2026-33314

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Description

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoofing vulnerability in the @local_check decorator allows unauthenticated external attackers to bypass local-only restrictions. This grants access to the Click'N'Load API endpoints, enabling attackers to remotely queue arbitrary downloads, leading to Server-Side Request Forgery (SSRF) and Denial of Service (DoS). This issue has been patched in version 0.5.0b3.dev97.

Basic Information

ID CVE-2026-33314
Source GitHub_M
Published Mar 24, 2026 at 18:52
Modified Mar 26, 2026 at 19:52

Affected Product

Vendor pyload
Product pyload
Version < 0.5.0b3.dev97
Affected Versions pyload pyload < 0.5.0b3.dev97

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.