<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T23:05:33.880443+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322583</id>
    <title>EUVD-2026-322583</title>
    <updated>2026-10-04T23:05:33.960527+00:00</updated>
    <content>EUVD-2026-322583</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46561</id>
    <title>fkie_cve-2026-46561</title>
    <updated>2026-10-04T23:05:33.960574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the is_global_host() check on the initial URL. This vulnerability is fixed in 0.5.0b3.dev100.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8rp3-xc6w-5qp5</id>
    <title>GHSA-8rp3-xc6w-5qp5 — pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API</title>
    <updated>2026-10-04T23:05:33.960611+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyload-ng</p>
<p>## Summary</p>
<p>The SSRF mitigation added in commit `33c55da` for GHSA-7gvf-3w72-p2pg is incomplete. The `PREREQFUNCTION`-based private IP check was correctly applied to `HTTPChunk` (download path) but not to `HTTPRequest` (used by the `parse_urls` API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the `is_global_host()` check on the initial URL.</p>
<p>## Details</p>
<p>The `parse_urls` API method validates the initial URL hostname:</p>
<p>```python
# src/pyload/core/api/__init__.py:600-604
if url:
    urlp = urlparse(url)
    hostname = urlp.hostname
    if urlp.scheme in ("http", "https") and hostname and is_global_host(hostname):
        page = get_url(url)
```</p>
<p>`get_url()` is imported from `request_factory.py` and creates an `HTTPRequest` with default settings:</p>
<p>```python
# src/pyload/core/network/request_factory.py:58-64
def get_url(self, *args, **kwargs):
    with HTTPRequest(None, self.get_options()) as h:
        rep = h.load(*args, **kwargs)
    return rep
```</p>
<p>`HTTPRequest.__init__` sets `allow_private_ip = True` by default:</p>
<p>```python
# src/pyload/core/network/http/http_request.py:75
self.allow_private_ip = True
```</p>
<p>The `init_handle()` method enables redirect following:</p>
<p>```python
# src/pyload/core/network/http/http_request.py:117-118
self.c.setopt(pycurl.FOLLOWLOCATION, 1)
self.c.setopt(pycurl.MAXREDIRS, 10)
```</p>
<p>The `_pre_request_callback` that should block redirec…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8rp3-xc6w-5qp5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2991</id>
    <title>PYSEC-2026-2991 — pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API</title>
    <updated>2026-10-04T23:05:33.960673+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyload-ng</p>
<p>## Summary</p>
<p>The SSRF mitigation added in commit `33c55da` for GHSA-7gvf-3w72-p2pg is incomplete. The `PREREQFUNCTION`-based private IP check was correctly applied to `HTTPChunk` (download path) but not to `HTTPRequest` (used by the `parse_urls` API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the `is_global_host()` check on the initial URL.</p>
<p>## Details</p>
<p>The `parse_urls` API method validates the initial URL hostname:</p>
<p>```python
# src/pyload/core/api/__init__.py:600-604
if url:
    urlp = urlparse(url)
    hostname = urlp.hostname
    if urlp.scheme in ("http", "https") and hostname and is_global_host(hostname):
        page = get_url(url)
```</p>
<p>`get_url()` is imported from `request_factory.py` and creates an `HTTPRequest` with default settings:</p>
<p>```python
# src/pyload/core/network/request_factory.py:58-64
def get_url(self, *args, **kwargs):
    with HTTPRequest(None, self.get_options()) as h:
        rep = h.load(*args, **kwargs)
    return rep
```</p>
<p>`HTTPRequest.__init__` sets `allow_private_ip = True` by default:</p>
<p>```python
# src/pyload/core/network/http/http_request.py:75
self.allow_private_ip = True
```</p>
<p>The `init_handle()` method enables redirect following:</p>
<p>```python
# src/pyload/core/network/http/http_request.py:117-118
self.c.setopt(pycurl.FOLLOWLOCATION, 1)
self.c.setopt(pycurl.MAXREDIRS, 10)
```</p>
<p>The `_pre_request_callback` that should block redirec…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2991"/>
  </entry>
</feed>
