Junglewise Threat Intelligence

CVE-2026-33314: pyload-ng auth bypass via Host header spoofing in Click'N'Load API

CVE-2026-33314 · Severity: medium · CVSS 6.5 · Published 2026-03-19

Technologies: pyload-ng (PyPI), pyLoad Next Generation. Vendors: PyPI, pyLoad.

Executive brief

A security flaw in pyload-ng, a popular download management tool, allows remote attackers to bypass security checks intended to restrict certain features to local users. By tricking the system into thinking a request is coming from the local machine, an attacker can remotely add unauthorized files to the download queue. This can lead to the server being used to attack other systems or being overwhelmed by massive, unwanted downloads.

Technical details

A Host Header Spoofing vulnerability exists in the `@local_check` decorator within `src/pyload/webui/app/blueprints/cnl_blueprint.py`. The implementation incorrectly trusts the user-controlled `HTTP_HOST` header to verify if a request originated from localhost. An unauthenticated remote attacker can bypass this check by providing a spoofed header (e.g., `Host: 127.0.0.1:9666`), gaining access to protected Click'N'Load API endpoints such as `/flash/add`. This allows attackers to perform Server-Side Request Forgery (SSRF) by queuing arbitrary URLs or cause a Denial of Service (DoS) by exhausting disk space and bandwidth. The issue is fixed in version 0.5.0b3.dev97.

Affected products

  • pyload pyload-ng <= 0.5.0b3.dev96

Timeline

  • 2026-03-19: advisory: GitHub Advisory published
  • 2026-03-19: patched: Fix released in version 0.5.0b3.dev97

References

Related threats