Arbitrary URL Fetching Vulnerability in pyLoad Download Manager
CVE-2026-35187
7.7HIGH
What is CVE-2026-35187?
The pyLoad download manager contains a vulnerability in its parse_urls API function, allowing authenticated users with ADD permissions to perform arbitrary URL fetches without proper validation. This flaw enables the retrieval of sensitive internal network resources and cloud metadata endpoints, as well as unauthorized access to local files through the file:// protocol. Furthermore, attackers can exploit gopher:// and dict:// protocols to interact with internal services and potentially enumerate file existence through error-based techniques.
Affected Version(s)
pyload <= 0.5.0b3.dev96
