← Back to CVEs
CVE-2026-33511
CRITICAL9.8
Description
pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofing. This allows unauthenticated remote users to access localhost-restricted endpoints, enabling them to inject arbitrary downloads, write files to the storage directory, and execute JavaScript code. This issue has been patched in version 0.5.0b3.dev97.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published3/24/2026
Last Modified3/26/2026
Sourcenvd
Honeypot Sightings0
Affected Products
pyload-ng_project:pyload-ngpyload:pyload
Weaknesses (CWE)
CWE-639
References
https://github.com/pyload/pyload/security/advisories/GHSA-g5j2-gxqh-x7pw(security-advisories@github.com)
https://github.com/pyload/pyload/security/advisories/GHSA-g5j2-gxqh-x7pw(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.