CVE-2026-42312
- EPSS 0.17%
- Veröffentlicht 11.05.2026 18:16:34
- Zuletzt bearbeitet 15.05.2026 14:09:19
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained...
CVE-2026-42313
- EPSS 0.4%
- Veröffentlicht 11.05.2026 18:16:34
- Zuletzt bearbeitet 15.05.2026 14:04:39
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained...
CVE-2026-41133
- EPSS 0.33%
- Veröffentlicht 21.04.2026 23:41:06
- Zuletzt bearbeitet 27.04.2026 19:28:39
pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin c...
CVE-2026-40594
- EPSS 0.17%
- Veröffentlicht 21.04.2026 17:14:03
- Zuletzt bearbeitet 27.04.2026 19:43:46
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/app/__init__.py reads the X-Forwarded-Proto header from any HTTP request without val...
CVE-2026-40071
- EPSS 0.22%
- Veröffentlicht 09.04.2026 18:17:03
- Zuletzt bearbeitet 28.04.2026 00:53:26
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abort_link WebUI JSON endpoints enforce weaker permissions than the core API methods they invoke. This a...
CVE-2026-35592
- EPSS 0.26%
- Veröffentlicht 07.04.2026 16:11:38
- Zuletzt bearbeitet 16.04.2026 21:11:52
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() function in src/pyload/plugins/extractors/UnTar.py uses os.path.commonprefix() for its path traversal check, which performs character-...
CVE-2026-35586
- EPSS 0.14%
- Veröffentlicht 07.04.2026 16:09:11
- Zuletzt bearbeitet 16.04.2026 18:54:32
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses incorrect option names ssl_cert and ssl_key, while the actual configuration option n...
CVE-2026-35464
- EPSS 0.53%
- Veröffentlicht 07.04.2026 14:38:02
- Zuletzt bearbeitet 23.04.2026 15:13:57
pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config options. The storage_folder option is not in this set and...
CVE-2026-35463
- EPSS 0.82%
- Veröffentlicht 07.04.2026 14:32:44
- Zuletzt bearbeitet 24.04.2026 15:18:49
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to admin...
CVE-2026-35459
- EPSS 0.28%
- Veröffentlicht 06.04.2026 19:37:00
- Zuletzt bearbeitet 24.07.2026 21:10:00
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to BaseDownloader.download() that checks ...