Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

pyload — Vulnerabilities & Security Advisories 38

All 38 CVE vulnerabilities found in pyload, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the Python-based download management tool pyload, focusing specifically on weakness types affecting the application and its dependencies. The collection covers reported security flaws disclosed for pyload, spanning the available historical record from its initial releases through recent updates, including issues in dependency libraries and core components. Here, users can track the vendor's security advisories, understand the specific classes of weaknesses such as input validation errors or improper resource management, and look up the complete vulnerability history for this product to assess risk and prioritize remediation efforts.

Vendor: pyload

CVE ID Title CVSS Severity Published
CVE-2026-48987 pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager CWE-400 6.5 Medium 2026-09-15
CVE-2026-48737 pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs CWE-918 4.9 Medium 2026-09-15
CVE-2026-45306 pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory CWE-706 6.5 Medium 2026-05-28
CVE-2026-45348 pyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js template literal CWE-79 8.7 High 2026-05-28
CVE-2026-46561 pyLoad: SSRF via HTTP Redirect Bypass in parse_urls API CWE-918 5.0 Medium 2026-05-28
CVE-2026-44226 pyLoad: Unauthenticated traceback disclosure via global exception handler in WebUI CWE-209 5.3 Medium 2026-05-11
CVE-2026-42315 pyLoad: Path Traversal via Package Folder Name in set_package_data CWE-22 8.1 High 2026-05-11
CVE-2026-42314 pyLoad: Path Traversal via Package Folder Name CWE-22 6.5 Medium 2026-05-11
CVE-2026-42312 pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification CWE-295 6.8 Medium 2026-05-11
CVE-2026-42313 pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy CWE-441 8.3 High 2026-05-11
CVE-2026-41133 pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass) CWE-613 8.8 High 2026-04-21
CVE-2026-40594 pyLoad: Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition) CWE-346 4.8 Medium 2026-04-21
CVE-2026-40071 pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions CWE-863 5.4 Medium 2026-04-09
CVE-2026-35592 pyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypass CWE-22 5.3 Medium 2026-04-07
CVE-2026-35586 Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng CWE-863 6.8 Medium 2026-04-07
CVE-2026-35464 pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and code execution CWE-502 7.5 High 2026-04-07
CVE-2026-35463 pyLoad has Improper Neutralization of Special Elements used in an OS Command CWE-78 8.8 High 2026-04-07
CVE-2026-35459 pyLoad has SSRF fix bypass via HTTP redirect CWE-918 4.6AI Medium AI 2026-04-06
CVE-2026-35187 pyLoad has SSRF in parse_urls API endpoint via unvalidated URL parameter CWE-918 7.7 High 2026-04-06
CVE-2026-33992 pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration CWE-918 7.7 - 2026-03-27
CVE-2026-33511 pyload-ng: Authentication Bypass via Host Header Injection in ClickNLoad CWE-639 8.2 - 2026-03-24
CVE-2026-33509 pyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration CWE-269 7.5 High 2026-03-24
CVE-2026-33314 pyload-ng: Improper Authentication and Origin Validation Error CWE-287 6.5 Medium 2026-03-24
CVE-2026-32808 pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verification CWE-22 8.1 High 2026-03-20
CVE-2026-29778 pyLoad: Arbitrary File Write via Path Traversal in edit_package() CWE-23 7.1 High 2026-03-07
CVE-2025-61773 pyLoad CNL and captcha handlers allow code Injection via unsanitized parameters CWE-74 8.1 High 2025-10-09
CVE-2025-57751 Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs CWE-400 6.5AI Medium AI 2025-08-21
CVE-2025-55156 PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter CWE-89 9.1AI Critical AI 2025-08-11
CVE-2025-54802 pyLoad CNL Blueprint is vulnerable to Path Traversal through `dlc_path` leading to Remote Code Execution (RCE) CWE-22 9.8 Critical 2025-08-05
CVE-2025-54140 pyLoad has Path Traversal Vulnerability in json/upload Endpoint that allows Arbitrary File Write CWE-22 7.5 High 2025-07-22

All 38 known CVE vulnerabilities affecting pyload with full Chinese analysis, references, and POCs where available.