CVE-2026-42312: pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification

Published May 4, 2026
·
Updated

Summary

The setconfigvalue() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/init.py gates security-sensitive options behind a hand-maintained allowlist ADMINONLYCOREOPTIONS. The option ("general", "sslverify") is not on that allowlist. Any authenticated user with the non-admin SETTINGS permission can set general.sslverify = off, and every subsequent outbound pycurl request is made with SSLVERIFYPEER=0 and SSLVERIFYHOST=0 — TLS peer and hostname verification are fully disabled. An on-path attacker can then present forged certificates for any hostname pyload fetches.

This is a direct continuation of the fix family CVE-2026-33509 / CVE-2026-35463 / CVE-2026-35464 / CVE-2026-35586, each of which patched a different missed option in the same allowlist.

Details

Writer — src/pyload/core/api/init.py, setconfigvalue() (around lines 215–290). The function is decorated with @permission(Perms.SETTINGS) and only rejects writes when (category, option) appears in ADMINONLYCOREOPTIONS:

python ADMINONLYCOREOPTIONS = { ("general", "storagefolder"), ("log", "sysloghost"), ("log", "syslogport"), ("proxy", "password"), ("proxy", "username"), ("reconnect", "script"), ("webui", "host"), ("webui", "sslcertfile"), ("webui", "sslkeyfile"), ("webui", "sslcertchain"), ("webui", "usessl"), } ... if (category, option) in ADMINONLYCOREOPTIONS and not isadmin: self.pyload.log.error(...); return self.pyload.config.set(category, option, value)

("general", "sslverify") is absent. config.set() in src/pyload/core/config/parser.py:329 calls cast() which has no branch for enum-string types — "off" is stored verbatim and persisted to disk via self.save().

Reader — src/pyload/core/network/requestfactory.py:109-110:

python def getoptions(self): return { "interface": self.iface(), "proxies": self.getproxies(), "ipv6": self.pyload.config.get("download", "ipv6"), "sslverify": self.pyload.config.get("general", "sslverify"), ... }

Sink — src/pyload/core/network/http/httprequest.py:193-206:

python if "sslverify" in options: aiachaseron = b"on (using aia-chaser)" if options["sslverify"] in [True, b"on", aiachaseron]: ... sslverify = 1 else: sslverify = 0 self.c.setopt(pycurl.SSLVERIFYPEER, sslverify) self.c.setopt(pycurl.SSLVERIFYHOST, sslverify 2)

Because getoptions() is invoked every time a new pycurl handle is built, the new config value takes effect on the very next outbound request — no pyload restart required.

PoC

Authenticated as any user who has Perms.SETTINGS but is not admin (e.g. a user with Role.USER + the SETTINGS permission bit):

bash 1) Log in as the SETTINGS (non-admin) user. curl -c cookies.txt -X POST http://pyload.example:8000/api/login \ -d 'username=settingsuser&password=<password>'

2) Disable TLS verification for all outbound downloads. curl -b cookies.txt -X POST http://pyload.example:8000/api/setConfigValue \ -d 'category=general&option=sslverify&value=off&section=core' -> 200 OK. Config persisted.

3) Enqueue any HTTPS download. An on-path attacker (shared LAN, compromised upstream router, DNS hijack, or a malicious proxy enabled via the sibling advisory on the proxy. options) can now present a forged cert for any target — pyload accepts it.

Verification: observe pycurl SSLVERIFYPEER=0 in a debug build, or confirm that a download from an HTTPS endpoint served with a self-signed / mismatched cert succeeds after step 2 and fails before it.

Impact

- Who: any authenticated user whose role was granted Perms.SETTINGS. In multi-user pyload deployments that delegate settings administration to non-admins, this is an unintended privilege escalation from "can change UI/download settings" to "can silently disable TLS cert validation for all outbound fetches". - What: 1. Man-in-the-middle on all HTTPS downloads, captcha fetches, update checks, and plugin HTTP calls. 2. Extends the impact of the already-published SSRF chain (CVE-2026-33992 / CVE-2026-35459). The URL-hostname validation those patches added is only meaningful if the TLS channel authenticates the endpoint; with sslverify=off, an on-path attacker can present forged certs for already-validated hosts — so HTTPS cloud-metadata endpoints and internal HTTPS services behind the host allowlist become reachable again. 3. Silent to the admin. Every adjacent security-critical option (proxy.password, SSL certfile/keyfile/certchain, usessl) is already admin-only, so the admin's mental model is that TLS policy cannot be weakened by a non-admin. - Not impacted: unauthenticated attackers; users holding only DOWNLOAD / LIST roles.

Other sources

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the setconfigvalue() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/init.py gates security-sensitive options behind a hand-maintained allowlist ADMINONLYCOREOPTIONS. The option ("general", "sslverify") is not on that allowlist. Any authenticated user with the non-admin SETTINGS permission can set general.sslverify = off, and every subsequent outbound pycurl request is made with SSLVERIFYPEER=0 and SSLVERIFYHOST=0 — TLS peer and hostname verification are fully disabled. An on-path attacker can then present forged certificates for any hostname pyload fetches. This is a direct continuation of the fix family CVE-2026-33509 / CVE-2026-35463 / CVE-2026-35464 / CVE-2026-35586, each of which patched a different missed option in the same allowlist. This vulnerability is fixed in 0.5.0b3.dev100.

— MITRE

Affected Software

2 affected componentsFixes available
pip/pyload-ng<=0.5.0b3.dev99
0.5.0b3.dev100
Pyload-ng Project Pyload-ng Python<0.5.0b3.dev100

Event History

May 4, 2026
Advisory Published
via GitHub·10:07 PM
Data Sourced
via GitHub·10:07 PM
DescriptionSeverityWeaknessAffected Software
May 11, 2026
CVE Published
via MITRE·04:32 PM
Data Sourced
via MITRE·04:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-42312?

CVE-2026-42312 is considered a high severity vulnerability due to the exposure of security-sensitive options without proper access controls.

2

How do I fix CVE-2026-42312?

To fix CVE-2026-42312, ensure that the option ('general', 'ssl_verify') is added to the ADMIN_ONLY_CORE_OPTIONS allowlist.

3

Who is affected by CVE-2026-42312?

CVE-2026-42312 affects users of the pyload-ng package versions up to and including 0.5.0b3.dev99.

4

What component does CVE-2026-42312 impact?

CVE-2026-42312 specifically impacts the set_config_value() API method in the pyload-ng application.

5

Can CVE-2026-42312 lead to any potential attacks?

Yes, CVE-2026-42312 could allow authenticated users to modify security-sensitive configurations, potentially leading to unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203