CVE-2026-33511 HIGH

CVE-2026-33511: pyload-ng: Authentication Bypass via Host Header Injection in ClickNLoad

Vendor Pyload
Product pyload
Weakness CWE-639 · IDOR
Published March 24, 2026
Last update March 25, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:L/SA:N

What the vulnerability does

01Description

pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofing. This allows unauthenticated remote users to access localhost-restricted endpoints, enabling them to inject arbitrary downloads, write files to the storage directory, and execute JavaScript code. This issue has been patched in version 0.5.0b3.dev97.

Key dates

02Disclosure timeline

March 24, 2026 CVE published
March 25, 2026 Record updated