CVE-2026-40594Disclosure(pyload-ng_project / pyload-ng)

LOWCVSS 4.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/app/__init__.py reads the X-Forwarded-Proto header from any HTTP request without validating that the request originates from a trusted proxy, then mutates the global Flask configuration SESSION_COOKIE_SECURE on every request. Because pyLoad uses the multi-threaded Cheroot WSGI server (request_queue_size=512), this creates a race condition where an attacker's request can influence the Secure flag on other users' session cookies — either downgrading cookie security behind a TLS proxy or causing a session denial-of-service on plain HTTP deployments. This vulnerability is fixed in 0.5.0b3.dev98.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pyload-ng

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-21)
  • 3 total mentions across 2 days

Affected systems

Products
pyload-ng

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-16: 1Mentions · 2026-04-21: 2Technical Details · 2026-04-16: 104-1604-21
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-161
Disclosure1
2026-04-212
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40594 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/… https://www.cve.org/CVERecord?id=CVE-2026-40594 ----- Traducción: CVE-2026-40594 pyL… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑40594 for pyLoad and links to the official CVE record, but offers no further technical or exploit details.

    0000033
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40594 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/… https://www.cve.org/CVERecord?id=CVE-2026-40594

    Post summary

    The post references CVE-2026-40594 for pyLoad, noting a pre-0.5.0b3 dev98 vulnerable handler, but offers no proof-of-concept, exploit details, patch information, or technical depth beyond the code location.

    00000174
    57.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 pyLoad (pyload/pyload), Race Condition (CWE-362) leading to Session Cookie Security Downgrade and Denial of Service, #CVE-2026-40594 (Medium) https://dailycve.com/pyload-pyload-pyload-race-condition-cwe-362-leading-to-session-cookie-security-downgrade-and-denial-of-service-cve-2026-40594-medium/

    Post summary

    The post announces CVE‑2026‑40594, describing a race condition in pyLoad that can downgrade session cookie security and cause a denial‑of‑service, but provides no exploit details, PoC, or exploitation evidence.

    0000030
    181 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppyload-ng_projectpyload-ng-python-

Explore more