CVE-2026-35459Disclosure(pyload-ng_project / pyload-ng)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch pyload-ng_project pyload-ng systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to BaseDownloader.download() that checks the hostname of the initial download URL. However, pycurl is configured with FOLLOWLOCATION=1 and MAXREDIRS=10, causing it to automatically follow HTTP redirects. Redirect targets are never validated against the SSRF filter. An authenticated user with ADD permission can bypass the SSRF fix by submitting a URL that redirects to an internal address.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pyload-ng

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-04-06)
  • 5 total mentions across 2 days

Affected systems

Products
pyload-ng

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-04: 1Mentions · 2026-04-06: 4PoC Mentioned / Linked · 2026-04-06: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-06: 404-0404-06
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-041
Disclosure1
2026-04-064
Disclosure4
Full discourse5 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35459 pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The … https://www.cve.org/CVERecord?id=CVE-2026-35459 ----- Traducción: CVE-2026-35459 pyL… http://infoflow.cloud`

    Post summary

    The post announces the disclosure of CVE-2026-35459 as an SSRF vulnerability in pyLoad without providing PoC, exploit, or patch information.

    0000028
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35459 pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The … https://www.cve.org/CVERecord?id=CVE-2026-35459

    Post summary

    The text announces an SSRF vulnerability in pyLoad version 0.5.0b3.dev96 and earlier, providing technical detail about the affected software.

    00000160
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35459: pyLoad has SSRF fix bypass via H... Classic redirect bypass - pycurl's FOLLOWLOCATION=1 makes their SSRF patch worthless, any authenticated user can pivot ... https://zerodaysignal.com/vulnerability/CVE-2026-35459 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text announces CVE-2026-35459, describing a bypass of pyLoad's SSRF protection via redirection, but does not provide exploit code or patch information.

    0000075
    204 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨 Critical pyload-ng flaw: CVE-2026-35459 Authenticated users may bypass SSRF protections via HTTP redirects and access sensitive internal resources. Update now or apply the recommended fix. 🔗 https://vulert.com/vuln-db/CVE-2026-35459 #CyberSecurity #pyloadng #CVE202635459 #Vulert https://t.co/mkBf9L5CAF

    Post summary

    The tweet announces a critical SSRF flaw (CVE-2026-35459) in pyload-ng that allows authenticated users to bypass protections via redirects, urging users to update or apply the recommended fix.

    0000035
    124 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical SSRF filter bypass (CVE-2026-35459) affects `pyLoad`, enabling access to internal network resources. This is an incomplete fix for CVE-2026-33992. #SSRF #pyLoad #infosec https://www.pulsepatch.io/posts/cve-2026-35459-pyload-ssrf-bypass

    Post summary

    The post announces a critical SSRF filter bypass in pyLoad, giving a short technical description but lacking explicit PoC, exploit code, or mitigation details.

    0000060
    11 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppyload-ng_projectpyload-ng-python-

Explore more