Server-Side Request Forgery Vulnerability in PyLoad Download Manager
CVE-2026-33992
9.3CRITICAL
What is CVE-2026-33992?
The PyLoad download manager has a vulnerability that allows an unauthenticated attacker to send arbitrary URLs to its download engine, which lacks proper validation. This flaw enables Server-Side Request Forgery (SSRF) attacks, potentially exposing sensitive internal network services. By exploiting this vulnerability, attackers can gain unauthorized access to critical infrastructure details on cloud providers such as DigitalOcean droplets. Sensitive information, including droplet IDs, network configurations, and authentication keys, can be exfiltrated, presenting a significant security risk. A patch has been implemented in version 0.5.0b3.dev97.
Affected Version(s)
pyload < 0.5.0b3.dev97
