Arbitrary URL Fetching Vulnerability in pyLoad Download Manager
CVE-2026-35187

7.7HIGH

Key Information:

Vendor

Pyload

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-35187?

The pyLoad download manager contains a vulnerability in its parse_urls API function, allowing authenticated users with ADD permissions to perform arbitrary URL fetches without proper validation. This flaw enables the retrieval of sensitive internal network resources and cloud metadata endpoints, as well as unauthorized access to local files through the file:// protocol. Furthermore, attackers can exploit gopher:// and dict:// protocols to interact with internal services and potentially enumerate file existence through error-based techniques.

Affected Version(s)

pyload <= 0.5.0b3.dev96

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.