CVE-2026-33511

CRITICALCVSS 9.8/10EPSS 0.42%

Last modified

CVE-2026-33511 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofing. EPSS estimates a 0.42% chance of exploitation in the next 30 days.

Description

pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofing. This allows unauthenticated remote users to access localhost-restricted endpoints, enabling them to inject arbitrary downloads, write files to the storage directory, and execute JavaScript code. This issue has been patched in version 0.5.0b3.dev97.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersions
PyloadPyload<= 0.4.20
Pyload-Ng ProjectPyload-Ng>= 0.5.0a5.dev528, < 0.5.0b3.dev97

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-33511?
pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofing. This allows unauthenticated remote users to access localhost-restricted endpoints, enabling them to inject arbitrary downloads, write files to the storage directory, and execute JavaScript code. This issue has been patched in version 0.5.0b3.dev97.
How severe is CVE-2026-33511?
CVE-2026-33511 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.42% probability of exploitation in the next 30 days.
How do I fix CVE-2026-33511?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-33511?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST