Open Source Download Manager Affected by Information Disclosure Flaw
CVE-2026-44226

5.3MEDIUM

Key Information:

Vendor

Pyload

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-44226?

The pyLoad download manager is susceptible to an information disclosure vulnerability that can be exploited by unauthenticated users. Prior to version 0.5.0b3.dev100, the WebUI of pyLoad incorrectly exposes full Python traceback details upon encountering unhandled exceptions. This flaw allows an attacker to manipulate template names and trigger server exceptions without any authentication. As a result, sensitive internal stack traces are returned in the HTTP responses, potentially revealing critical server configuration details and increasing the risk of further attacks.

Affected Version(s)

pyload < 0.5.0b3.dev100

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.