Junglewise Threat Intelligence

CVE-2026-33992: PYSEC-2026-497 - pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration

CVE-2026-33992 · Severity: medium · CVSS 4 · Published 2026-06-29

Technologies: pyload-ng (PyPI). Vendors: PyPI.

Executive brief

pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration

Affected products

  • PyPI pyload-ng

Related threats