CVE-2026-33992Disclosure(pyload / pyload)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch pyload pyload systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs without validation, enabling Server-Side Request Forgery (SSRF) attacks. An authenticated attacker can exploit this to access internal network services and exfiltrate cloud provider metadata. On DigitalOcean droplets, this exposes sensitive infrastructure data including droplet ID, network configuration, region, authentication keys, and SSH keys configured in user-data/cloud-init. Version 0.5.0b3.dev97 contains a patch.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pyload

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Exploit: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-28); latest day: 2
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
pyload

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-03-27: 1Mentions · 2026-03-28: 2Mentions · 2026-04-04: 1Mentions · 2026-04-05: 1Mentions · 2026-08-13: 2PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-04-04: 1PoC Mentioned / Linked · 2026-08-13: 1Patch / Workaround · 2026-03-28: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 2Technical Details · 2026-04-04: 1Technical Details · 2026-04-05: 1Technical Details · 2026-08-13: 203-2703-2804-0404-0508-13
Signal classification3 categories
Disclosure
571.4%
Exploit
114.3%
PoC
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-03-282
Disclosure2
2026-04-041
Disclosure1
2026-04-051
Disclosure1
2026-08-132
Exploit1PoC1
Full discourse7 posts
  • Pentester Academy@SecurityTube
    Exploit

    A server only needs one unchecked URL to become an attacker’s proxy. Investigate CVE-2026-33992, exploit pyLoad’s SSRF flaw, and reach internal services in this 30-minute Skill Dive lab. Control the request. Cross the boundary. ⤵️ https://bit.ly/4xTI6T9 https://t.co/zCF9z4ZPhs

    Post summary

    The post advertises a 30‑minute lab that demonstrates how to exploit the pyLoad SSRF vulnerability (CVE‑2026‑33992) by turning a server into an attacker‑driven proxy, but it does not provide any code or active exploitation evidence.

    010542.9K
    199.3K followersView on X
  • INE Security (FKA eLearnSecurity)@INEsecurity
    PoC

    A server only needs one unchecked URL to become an attacker’s proxy. Investigate CVE-2026-33992, exploit pyLoad’s SSRF flaw, and reach internal services in this 30-minute Skill Dive lab. Control the request. Cross the boundary. ⤵️ https://bit.ly/3TPwt0E https://t.co/AV134GhufB

    Post summary

    The post points to a lab-based proof of concept demonstrating how CVE-2026-33992 allows an attacker to use pyLoad as a proxy via unchecked URLs.

    000101.3K
    47.3K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 pyload, SSRF Bypass via Automatic Redirect Following, #CVE-2026-33992 (High) https://dailycve.com/pyload-ssrf-bypass-via-automatic-redirect-following-cve-2026-33992-high/

    Post summary

    The post announces a new SSRF bypass vulnerability (CVE-2026-33992) in pyload, detailing its mechanism without providing PoC, exploit code, or patch information.

    0000054
    175 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical SSRF filter bypass (CVE-2026-35459) affects `pyLoad`, enabling access to internal network resources. This is an incomplete fix for CVE-2026-33992. #SSRF #pyLoad #infosec https://www.pulsepatch.io/posts/cve-2026-35459-pyload-ssrf-bypass

    Post summary

    A critical SSRF filter bypass (CVE‑2026‑35459) in pyLoad is announced, linking to a Pulsepatch article, but no exploit code or active exploitation claims are provided.

    0000060
    11 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Server-Side Request Forgery (SSRF) in `pyLoad` (CVE-2026-33992) can lead to cloud metadata exfiltration. Assess `pyLoad` deployments and restrict network egress. #SSRF #CloudSecurity #InfoSec https://www.pulsepatch.io/posts/cve-2026-33992-pyload-ssrf-cloud-metadata

    Post summary

    The post announces a new SSRF vulnerability in pyLoad (CVE‑2026‑33992) that could expose cloud metadata, and recommends limiting network egress as mitigation.

    0000030
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33992 pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs without validatio… https://www.cve.org/CVERecord?id=CVE-2026-33992

    Post summary

    The text announces CVE-2026-33992, noting that prior to version 0.5.0b3.dev97, pyLoad’s download engine improperly accepts arbitrary URLs. No PoC, exploit, or patch is described.

    0000065
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33992: pyLoad:... PyLoad's blind URL acceptance turns your download manager into a cloud metadata harvesting tool - DigitalOcean SSH keys anyone? #SSRF #CloudSec. https://zerodaysignal.com/vulnerability/CVE-2026-33992 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑33992, highlighting a blind URL acceptance flaw in PyLoad that enables SSRF cloud‑metadata harvesting (potentially exposing DigitalOcean SSH keys). No patch, exploit code, or active exploitation evidence is provided, though a link to a vulnerability page is included.

    0000088
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppyloadpyload0.5.0--

Explore more