Server-Side Request Forgery Vulnerability in PyLoad Download Manager
CVE-2026-33992

9.3CRITICAL

Key Information:

Vendor

Pyload

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33992?

The PyLoad download manager has a vulnerability that allows an unauthenticated attacker to send arbitrary URLs to its download engine, which lacks proper validation. This flaw enables Server-Side Request Forgery (SSRF) attacks, potentially exposing sensitive internal network services. By exploiting this vulnerability, attackers can gain unauthorized access to critical infrastructure details on cloud providers such as DigitalOcean droplets. Sensitive information, including droplet IDs, network configurations, and authentication keys, can be exfiltrated, presenting a significant security risk. A patch has been implemented in version 0.5.0b3.dev97.

Affected Version(s)

pyload < 0.5.0b3.dev97

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.