CVE-2026-42312: pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification
Summary
The setconfigvalue() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/init.py gates security-sensitive options behind a hand-maintained allowlist ADMINONLYCOREOPTIONS. The option ("general", "sslverify") is not on that allowlist. Any authenticated user with the non-admin SETTINGS permission can set general.sslverify = off, and every subsequent outbound pycurl request is made with SSLVERIFYPEER=0 and SSLVERIFYHOST=0 — TLS peer and hostname verification are fully disabled. An on-path attacker can then present forged certificates for any hostname pyload fetches.
This is a direct continuation of the fix family CVE-2026-33509 / CVE-2026-35463 / CVE-2026-35464 / CVE-2026-35586, each of which patched a different missed option in the same allowlist.
Details
Writer — src/pyload/core/api/init.py, setconfigvalue() (around lines 215–290). The function is decorated with @permission(Perms.SETTINGS) and only rejects writes when (category, option) appears in ADMINONLYCOREOPTIONS:
python ADMINONLYCOREOPTIONS = { ("general", "storagefolder"), ("log", "sysloghost"), ("log", "syslogport"), ("proxy", "password"), ("proxy", "username"), ("reconnect", "script"), ("webui", "host"), ("webui", "sslcertfile"), ("webui", "sslkeyfile"), ("webui", "sslcertchain"), ("webui", "usessl"), } ... if (category, option) in ADMINONLYCOREOPTIONS and not isadmin: self.pyload.log.error(...); return self.pyload.config.set(category, option, value)
("general", "sslverify") is absent. config.set() in src/pyload/core/config/parser.py:329 calls cast() which has no branch for enum-string types — "off" is stored verbatim and persisted to disk via self.save().
Reader — src/pyload/core/network/requestfactory.py:109-110:
python def getoptions(self): return { "interface": self.iface(), "proxies": self.getproxies(), "ipv6": self.pyload.config.get("download", "ipv6"), "sslverify": self.pyload.config.get("general", "sslverify"), ... }
Sink — src/pyload/core/network/http/httprequest.py:193-206:
python if "sslverify" in options: aiachaseron = b"on (using aia-chaser)" if options["sslverify"] in [True, b"on", aiachaseron]: ... sslverify = 1 else: sslverify = 0 self.c.setopt(pycurl.SSLVERIFYPEER, sslverify) self.c.setopt(pycurl.SSLVERIFYHOST, sslverify 2)
Because getoptions() is invoked every time a new pycurl handle is built, the new config value takes effect on the very next outbound request — no pyload restart required.
PoC
Authenticated as any user who has Perms.SETTINGS but is not admin (e.g. a user with Role.USER + the SETTINGS permission bit):
bash 1) Log in as the SETTINGS (non-admin) user. curl -c cookies.txt -X POST http://pyload.example:8000/api/login \ -d 'username=settingsuser&password=<password>'
2) Disable TLS verification for all outbound downloads. curl -b cookies.txt -X POST http://pyload.example:8000/api/setConfigValue \ -d 'category=general&option=sslverify&value=off§ion=core' -> 200 OK. Config persisted.
3) Enqueue any HTTPS download. An on-path attacker (shared LAN, compromised upstream router, DNS hijack, or a malicious proxy enabled via the sibling advisory on the proxy. options) can now present a forged cert for any target — pyload accepts it.
Verification: observe pycurl SSLVERIFYPEER=0 in a debug build, or confirm that a download from an HTTPS endpoint served with a self-signed / mismatched cert succeeds after step 2 and fails before it.
Impact
- Who: any authenticated user whose role was granted Perms.SETTINGS. In multi-user pyload deployments that delegate settings administration to non-admins, this is an unintended privilege escalation from "can change UI/download settings" to "can silently disable TLS cert validation for all outbound fetches". - What: 1. Man-in-the-middle on all HTTPS downloads, captcha fetches, update checks, and plugin HTTP calls. 2. Extends the impact of the already-published SSRF chain (CVE-2026-33992 / CVE-2026-35459). The URL-hostname validation those patches added is only meaningful if the TLS channel authenticates the endpoint; with sslverify=off, an on-path attacker can present forged certs for already-validated hosts — so HTTPS cloud-metadata endpoints and internal HTTPS services behind the host allowlist become reachable again. 3. Silent to the admin. Every adjacent security-critical option (proxy.password, SSL certfile/keyfile/certchain, usessl) is already admin-only, so the admin's mental model is that TLS policy cannot be weakened by a non-admin. - Not impacted: unauthenticated attackers; users holding only DOWNLOAD / LIST roles.
Other sources
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the setconfigvalue() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/init.py gates security-sensitive options behind a hand-maintained allowlist ADMINONLYCOREOPTIONS. The option ("general", "sslverify") is not on that allowlist. Any authenticated user with the non-admin SETTINGS permission can set general.sslverify = off, and every subsequent outbound pycurl request is made with SSLVERIFYPEER=0 and SSLVERIFYHOST=0 — TLS peer and hostname verification are fully disabled. An on-path attacker can then present forged certificates for any hostname pyload fetches. This is a direct continuation of the fix family CVE-2026-33509 / CVE-2026-35463 / CVE-2026-35464 / CVE-2026-35586, each of which patched a different missed option in the same allowlist. This vulnerability is fixed in 0.5.0b3.dev100.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42312?
CVE-2026-42312 is considered a high severity vulnerability due to the exposure of security-sensitive options without proper access controls.
How do I fix CVE-2026-42312?
To fix CVE-2026-42312, ensure that the option ('general', 'ssl_verify') is added to the ADMIN_ONLY_CORE_OPTIONS allowlist.
Who is affected by CVE-2026-42312?
CVE-2026-42312 affects users of the pyload-ng package versions up to and including 0.5.0b3.dev99.
What component does CVE-2026-42312 impact?
CVE-2026-42312 specifically impacts the set_config_value() API method in the pyload-ng application.
Can CVE-2026-42312 lead to any potential attacks?
Yes, CVE-2026-42312 could allow authenticated users to modify security-sensitive configurations, potentially leading to unauthorized access.