Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-46561

Опубликовано: 28 мая 2026
Источник: debian
EPSS Низкий

Описание

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the is_global_host() check on the initial URL. This vulnerability is fixed in 0.5.0b3.dev100.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pyloaditppackage

EPSS

Процентиль: 7%
0.00176
Низкий

Связанные уязвимости

CVSS3: 5
nvd
3 месяца назад

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the is_global_host() check on the initial URL. This vulnerability is fixed in 0.5.0b3.dev100.

CVSS3: 5
github
3 месяца назад

pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API

EPSS

Процентиль: 7%
0.00176
Низкий