Executive brief
pyLoad is an open-source download manager used to automate file downloads. A security flaw allows authenticated users to trick the software into making requests to internal network services or cloud metadata endpoints that should be private. This could lead to the exposure of sensitive internal data, such as cloud credentials or private server information, potentially compromising the entire hosting environment.
Technical details
A server-side request forgery (SSRF) vulnerability exists in pyLoad due to an incomplete fix for a previous vulnerability. While the software validates the hostname of the initial download URL in BaseDownloader.download(), the underlying pycurl library is configured to follow up to 10 HTTP redirects (FOLLOWLOCATION=1) without re-validating the redirect targets. An authenticated attacker with 'ADD' permissions can provide a URL pointing to a malicious server that issues a 302 redirect to an internal IP address (e.g., 127.0.0.1 or 169.254.169.254). This allows the attacker to bypass the SSRF filter and retrieve sensitive data from internal services or cloud metadata endpoints. The issue is addressed in version 0.5.0b3.dev97.
Affected products
- pyLoad pyLoad <= 0.5.0b3.dev96
- pyLoad-ng project pyload-ng < 0.5.0b3.dev97
Timeline
- 2026-04-02: advisory: GitHub Security Advisory published
- 2026-04-06: disclosed: CVE published to NVD
- 2026-04-06: patched: Fix committed to repository