CVE-2026-33511·Python vulnerability
pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofing. This allows unauthenticated remote users to access localhost-restricted endpoints, enabling them to inject arbitrary downloads, write files to the storage directory, and execute JavaScript code. This issue has been patched in version 0.5.0b3.dev97.
- Severity
- critical
- Software
- Python
- Fixed in
- 0.5.0b3.dev97
- Published
- 2026-03-24
Affected versions
From: 0.5.0a5.dev528
Until: 0.5.0b3.dev97
Fixed in: 0.5.0b3.dev97
How to fix this CVE
Update pyLoad to version 0.5.0b3.dev97 or later to patch the Host header spoofing vulnerability in the ClickNLoad feature. This vulnerability allows remote attackers to bypass localhost restrictions and gain unauthorized access to sensitive endpoints. Immediately apply this update to prevent arbitrary file writes, malicious download injection, and JavaScript code execution.
sudo dnf update python3 && pip3 install --upgrade pyloadDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET /api/v1/downloads HTTP/1.1\r\nHost: localhost(:|$)|GET /api/v1/downloads HTTP/1.1\r\nHost: 127\.0\.0\.1|POST /api/v1/uploads HTTP/1.1.*Host: localhostWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block HTTP requests with Host header values of 'localhost', '127.0.0.1', or '::1' unless the request originates from the server's own IP address. Implement strict Host header validation and reject requests where the Host header does not match the configured server FQDN or whitelisted internal hosts.How to check if you are affected
- Run 'pip3 show pyload' or 'python3 -c "import pyload; print(pyload.__version__)"' to check the currently installed version of pyLoad
- Verify if pyLoad's ClickNLoad feature is enabled by checking the configuration file at ~/.pyload/settings.conf or /etc/pyload/settings.conf for 'clicknload' settings
- Search logs for GET/POST requests with Host header values that don't match your server's FQDN but target localhost endpoints like /api/v1/downloads
- Confirm the patch was applied by running 'pip3 show pyload' and verifying the version is 0.5.0b3.dev97 or higher
Indicators of compromise
- HTTP requests with Host: localhost targeting /api/v1/ endpoints
- Host header values of 127.0.0.1 or ::1 in external requests
- POST requests to /api/v1/downloads or /api/v1/uploads with spoofed Host headers
FAQ
What is CVE-2026-33511?
CVE-2026-33511 is a critical authentication bypass vulnerability in pyLoad's ClickNLoad feature where attackers can spoof HTTP Host headers to bypass the local_check security decorator. This allows unauthenticated remote access to restricted localhost endpoints, leading to arbitrary file writes and code execution.
Is CVE-2026-33511 being actively exploited?
According to CISA, CVE-2026-33511 is not currently listed in the Known Exploited Vulnerabilities catalog, and no public exploits have been released. However, the vulnerability is trivial to exploit and should be patched immediately.
What versions of pyLoad are affected by CVE-2026-33511?
pyLoad versions 0.5.0a5.dev528 through 0.5.0b3.dev96 are affected. Versions prior to 0.5.0a5.dev528 and 0.5.0b3.dev97 and later are not vulnerable.
How do I check if my server is vulnerable to CVE-2026-33511?
Run 'pip3 show pyload | grep Version' to get your installed version, then compare it against the affected range 0.5.0a5.dev528–0.5.0b3.dev96. If your version falls within this range, your system is vulnerable.
Does Defensia detect CVE-2026-33511?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If pyLoad is installed on a monitored server, CVE-2026-33511 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-33511. Free for 1 server.
Get started free