CVE-2026-33992: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33992 is a Server-Side Request Forgery (SSRF) vulnerability in pyLoad, a free and open-source download manager written in Python. The flaw allows authenticated attackers with low privileges to submit arbitrary URLs to pyLoad's download engine without any validation, enabling access to internal network services and cloud provider metadata endpoints. All pyLoad installations running version 0.5.0 (pyload-ng <= 0.5.0b3.dev96) are affected; the issue was disclosed on March 25, 2026, and published to the GitHub Advisory Database on March 27, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 9.3 (Critical) (Github Advisory, pyload Advisory).

Technical details

The root cause is CWE-918 (Server-Side Request Forgery): the /api/addPackage endpoint in src/pyload/webui/app/blueprints/api_blueprint.py splits user-supplied URLs from the form field add_links and passes them directly to api.add_package() without any destination validation. The download engine in src/pyload/core/managers/download.py then accepts any URL scheme and initiates HTTP requests to arbitrary destinations, including RFC 1918 private IP ranges and link-local cloud metadata addresses such as 169.254.169.254. Exploitation requires only a valid pyLoad user account (any role) and network connectivity to the pyLoad instance — no special privileges or user interaction beyond authentication are needed (pyload Advisory, Patch Commit).

Impact

Successful exploitation enables complete exfiltration of cloud instance metadata, including droplet IDs, public/private IP addresses, VPC topology, cloud IAM credentials (e.g., AWS), SSH public keys, API tokens, and secrets stored in cloud-init/user-data on platforms such as DigitalOcean, AWS EC2, Google Cloud, and Azure. Stolen credentials and SSH keys can facilitate lateral movement into internal network services and further infrastructure compromise. The vulnerability has no availability impact but poses a high confidentiality risk and, through subsequent credential abuse, a high integrity risk to downstream systems (Github Advisory, pyload Advisory).

Exploitability

A proof-of-concept (PoC) with step-by-step reproduction instructions, a live demo instance, and screenshots demonstrating successful metadata exfiltration is publicly available in the GitHub Security Advisory (pyload Advisory). The EPSS score is approximately 0.033% (0.082% per Feedly), indicating a currently low but non-negligible probability of exploitation in the wild. There is no confirmed evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible pyLoad instances running version 0.5.0 (pyload-ng <= 0.5.0b3.dev96) using network scanning tools or Shodan.
  2. Authentication: Log in to the pyLoad web interface using any valid account (ADMIN or USER role). The public PoC used credentials pyload / pyload on a demo instance.
  3. Navigate to package submission: Go to the "Package" tab in the pyLoad UI to access the download submission form.
  4. Inject SSRF payload: In the "Package Name" field, enter any name. In the "Link" field, enter the SSRF target URL, e.g., http://169.254.169.254/metadata/v1.json for DigitalOcean metadata, or http://169.254.169.254/latest/meta-data/iam/security-credentials/ for AWS IAM credentials.
  5. Trigger download: Submit the package. pyLoad's download engine will initiate an HTTP request to the specified internal/metadata endpoint without validation.
  6. Retrieve exfiltrated data: Navigate to the "Files" section and download the resulting file. The file will contain the cloud metadata response, including credentials, SSH keys, network configuration, and other sensitive infrastructure data (pyload Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the pyLoad server to 169.254.169.254 (DigitalOcean/AWS/GCP/Azure metadata), metadata.google.internal, or other RFC 1918/link-local addresses; unusual HTTP GET requests to internal IP ranges originating from the pyLoad process.
  • Logs: pyLoad application logs showing download requests to 169.254.169.254, 192.168.x.x, 10.x.x.x, or 172.16-31.x.x ranges; entries in the pyLoad download history for packages with internal or metadata endpoint URLs.
  • File System: Unexpected files in the pyLoad download directory containing JSON-formatted cloud metadata (e.g., v1.json, files with fields like droplet_id, interfaces, auth-key, public-keys); files containing AWS credential structures (AccessKeyId, SecretAccessKey, Token).
  • Process: The pyLoad Python process initiating HTTP connections to link-local or private IP addresses, observable via network monitoring tools (e.g., netstat, ss, or EDR telemetry) (pyload Advisory).

Mitigation and workarounds

Upgrade pyload-ng to version 0.5.0b3.dev97 or later, which introduces hostname and IP validation in the download engine — blocking requests to non-global (private/link-local) IP addresses before initiating downloads (Patch Commit). If immediate upgrade is not possible, implement network-level controls to block pyLoad's outbound access to 169.254.169.254, RFC 1918 ranges, and other internal metadata endpoints using firewall rules or security groups. Additionally, restrict pyLoad access to authenticated, trusted users only, and monitor download logs for requests targeting internal IP ranges (Github Advisory).

Community reactions

The vulnerability was reported by security researcher DhiyaneshGeek and published via GitHub Security Advisories on March 25, 2026. A Bluesky post referencing the CVE was observed shortly after disclosure, indicating some community awareness. Red Hat also tracked the vulnerability as of March 30, 2026. No major vendor statements beyond the pyLoad maintainer's patch or significant media coverage have been identified at this time (pyload Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management