CVE-2026-48987
- EPSS 0.3%
- Veröffentlicht 15.09.2026 14:41:43
- Zuletzt bearbeitet 16.09.2026 13:42:49
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid submitted to the authenticated ge...
CVE-2026-48737
- EPSS 0.18%
- Veröffentlicht 15.09.2026 14:40:27
- Zuletzt bearbeitet 16.09.2026 17:17:18
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/pyload/core/utils/web/check.py relies on Python's global-address classification without examining IPv4 destinations embedded in 6to...
CVE-2026-45306
- EPSS 0.23%
- Veröffentlicht 28.05.2026 17:12:59
- Zuletzt bearbeitet 29.05.2026 15:39:34
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR or userdir, but does NOT protect the Flask session directory (/tmp/pyLoad/flask). A...
CVE-2026-45348
- EPSS 0.2%
- Veröffentlicht 28.05.2026 17:12:20
- Zuletzt bearbeitet 29.05.2026 15:39:34
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates a stored link URL into a template literal inside si...
- EPSS 0.18%
- Veröffentlicht 28.05.2026 17:11:28
- Zuletzt bearbeitet 29.05.2026 15:39:34
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An authenticated attacker can supply a URL pointing t...
CVE-2026-44226
- EPSS 0.34%
- Veröffentlicht 11.05.2026 18:16:37
- Zuletzt bearbeitet 18.05.2026 18:25:05
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<path:filename> is reachable without authentication a...
CVE-2026-42315
- EPSS 0.4%
- Veröffentlicht 11.05.2026 18:16:35
- Zuletzt bearbeitet 15.05.2026 14:29:53
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_folder", there is no sanitization at all, allowing ...
CVE-2026-42314
- EPSS 0.34%
- Veröffentlicht 11.05.2026 18:16:35
- Zuletzt bearbeitet 15.05.2026 13:43:30
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. whi...
CVE-2026-42313
- EPSS 0.4%
- Veröffentlicht 11.05.2026 18:16:34
- Zuletzt bearbeitet 15.05.2026 14:04:39
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained...
CVE-2026-42312
- EPSS 0.17%
- Veröffentlicht 11.05.2026 18:16:34
- Zuletzt bearbeitet 15.05.2026 14:09:19
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained...