Executive brief
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
Affected products
- PyPI pyload-ng
Junglewise Threat Intelligence
CVE-2026-33992 · Severity: medium · CVSS 4 · Published 2026-06-29
Technologies: pyload-ng (PyPI). Vendors: PyPI.
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration