Technology · pyLoad
pyLoad Next Generation vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in pyLoad Next Generation: 0 in the last 7 days and 2 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-48987, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 2
- Exploited in the wild
- 0
About pyLoad Next Generation
A free and open-source download manager written in Python and designed to be extremely lightweight and easily extensible.
Latest pyLoad Next Generation vulnerabilities
- CVE-2026-48987: pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-48737: pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in…mediumCVSS 4.9EPSS 0.3%
- CVE-2026-46561: pyLoad SSRF via HTTP redirect bypass in parse_urls APImediumCVSS 5EPSS 0.3%
- CVE-2026-45348: pyLoad stored XSS in Downloads view via packages.js templatehighCVSS 8.7EPSS 0.4%
- CVE-2026-45306: pyLoad account takeover via session directory bypass in storage_foldermediumCVSS 6.5EPSS 0.4%
- CVE-2026-44226: pyLoad pyload-ng information disclosure in WebUI error handlermediumCVSS 5.3EPSS 0.4%
- CVE-2026-42315: pyLoad path traversal in set_package_data APIhighCVSS 8.1EPSS 0.5%
- CVE-2026-42314: pyLoad path traversal in package folder name sanitizationmediumCVSS 6.5EPSS 0.4%
- CVE-2026-42313: pyLoad incorrect authorization in proxy configuration settingshighCVSS 8.3EPSS 0.4%
- CVE-2026-42312: pyLoad improper authorization allows disabling TLS verificationmediumCVSS 6.8EPSS 0.2%
- CVE-2026-40594: pyLoad session cookie security downgrade via header spoofingmediumCVSS 4.8EPSS 0.2%
- CVE-2026-40071: pyload-ng improper authorization in WebUI JSON endpointsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-35592: pyload-ng path traversal in UnTar extractionmediumCVSS 5.3EPSS 0.4%
- CVE-2026-35586: pyload-ng authorization bypass in SSL configurationmediumCVSS 6.8EPSS 0.2%
- CVE-2026-35187: pyLoad SSRF and local file disclosure in parse_urls APIhighCVSS 7.7EPSS 0.4%
- CVE-2026-33314: pyload-ng auth bypass via Host header spoofing in Click'N'Load APImediumCVSS 6.5EPSS 0.2%
- CVE-2026-29778: pyLoad path traversal in edit_packagehighCVSS 7.1EPSS 0.5%
- CVE-2025-7346: pyLoad authentication bypass via Host header spoofing in local_checkhighCVSS 7.5EPSS 0.3%
- pyload-ng localhost restriction bypass allowing arbitrary package creationmediumCVSS 4
- pyload-ng RCE via js2py sandbox escapeinfoCVSS 9.8
- CVE-2024-47821: pyLoad remote code execution via flashgot API and scripts folder manipulationcriticalCVSS 9.1EPSS 0.7%
- CVE-2024-22416: pyLoad pyload-ng CSRF leading to admin privilege escalationcriticalCVSS 9.6EPSS 0.9%
Most severe pyLoad Next Generation vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-22416: pyLoad pyload-ng CSRF leading to admin privilege escalationcriticalCVSS 9.6EPSS 0.9%
- CVE-2024-47821: pyLoad remote code execution via flashgot API and scripts folder manipulationcriticalCVSS 9.1EPSS 0.7%
- CVE-2026-45348: pyLoad stored XSS in Downloads view via packages.js templatehighCVSS 8.7EPSS 0.4%
- CVE-2026-42313: pyLoad incorrect authorization in proxy configuration settingshighCVSS 8.3EPSS 0.4%
- CVE-2026-42315: pyLoad path traversal in set_package_data APIhighCVSS 8.1EPSS 0.5%
- CVE-2026-35187: pyLoad SSRF and local file disclosure in parse_urls APIhighCVSS 7.7EPSS 0.4%
- CVE-2025-7346: pyLoad authentication bypass via Host header spoofing in local_checkhighCVSS 7.5EPSS 0.3%
- CVE-2026-29778: pyLoad path traversal in edit_packagehighCVSS 7.1EPSS 0.5%
- CVE-2026-42312: pyLoad improper authorization allows disabling TLS verificationmediumCVSS 6.8EPSS 0.2%
- CVE-2026-35586: pyload-ng authorization bypass in SSL configurationmediumCVSS 6.8EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pyload-next-generation.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "pyLoad Next Generation vulnerabilities", https://junglewise.ai/threats/technologies/pyload-next-generation, 26 September 2026.