<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 17:08:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322583</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322583</link>
      <description>EUVD-2026-322583</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322583</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46561</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46561</link>
      <description>&lt;p&gt;pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the is_global_host() check on the initial URL. This vulnerability is fixed in 0.5.0b3.dev100.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the is_global_host() check on the initial URL. This vulnerability is fixed in 0.5.0b3.dev100.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46561</guid>
    </item>
    <item>
      <title>GHSA-8rp3-xc6w-5qp5 — pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8rp3-xc6w-5qp5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The SSRF mitigation added in commit `33c55da` for GHSA-7gvf-3w72-p2pg is incomplete. The `PREREQFUNCTION`-based private IP check was correctly applied to `HTTPChunk` (download path) but not to `HTTPRequest` (used by the `parse_urls` API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the `is_global_host()` check on the initial URL.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `parse_urls` API method validates the initial URL hostname:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/api/__init__.py:600-604
if url:
    urlp = urlparse(url)
    hostname = urlp.hostname
    if urlp.scheme in (&amp;#34;http&amp;#34;, &amp;#34;https&amp;#34;) and hostname and is_global_host(hostname):
        page = get_url(url)
```&lt;/p&gt;
&lt;p&gt;`get_url()` is imported from `request_factory.py` and creates an `HTTPRequest` with default settings:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/request_factory.py:58-64
def get_url(self, *args, **kwargs):
    with HTTPRequest(None, self.get_options()) as h:
        rep = h.load(*args, **kwargs)
    return rep
```&lt;/p&gt;
&lt;p&gt;`HTTPRequest.__init__` sets `allow_private_ip = True` by default:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/http/http_request.py:75
self.allow_private_ip = True
```&lt;/p&gt;
&lt;p&gt;The `init_handle()` method enables redirect following:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/http/http_request.py:117-118
self.c.setopt(pycurl.FOLLOWLOCATION, 1)
self.c.setopt(pycurl.MAXREDIRS, 10)
```&lt;/p&gt;
&lt;p&gt;The `_pre_request_callback` that should block redirec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The SSRF mitigation added in commit `33c55da` for GHSA-7gvf-3w72-p2pg is incomplete. The `PREREQFUNCTION`-based private IP check was correctly applied to `HTTPChunk` (download path) but not to `HTTPRequest` (used by the `parse_urls` API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the `is_global_host()` check on the initial URL.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `parse_urls` API method validates the initial URL hostname:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/api/__init__.py:600-604
if url:
    urlp = urlparse(url)
    hostname = urlp.hostname
    if urlp.scheme in (&amp;#34;http&amp;#34;, &amp;#34;https&amp;#34;) and hostname and is_global_host(hostname):
        page = get_url(url)
```&lt;/p&gt;
&lt;p&gt;`get_url()` is imported from `request_factory.py` and creates an `HTTPRequest` with default settings:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/request_factory.py:58-64
def get_url(self, *args, **kwargs):
    with HTTPRequest(None, self.get_options()) as h:
        rep = h.load(*args, **kwargs)
    return rep
```&lt;/p&gt;
&lt;p&gt;`HTTPRequest.__init__` sets `allow_private_ip = True` by default:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/http/http_request.py:75
self.allow_private_ip = True
```&lt;/p&gt;
&lt;p&gt;The `init_handle()` method enables redirect following:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/http/http_request.py:117-118
self.c.setopt(pycurl.FOLLOWLOCATION, 1)
self.c.setopt(pycurl.MAXREDIRS, 10)
```&lt;/p&gt;
&lt;p&gt;The `_pre_request_callback` that should block redirec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8rp3-xc6w-5qp5</guid>
    </item>
    <item>
      <title>PYSEC-2026-2991 — pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2991</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The SSRF mitigation added in commit `33c55da` for GHSA-7gvf-3w72-p2pg is incomplete. The `PREREQFUNCTION`-based private IP check was correctly applied to `HTTPChunk` (download path) but not to `HTTPRequest` (used by the `parse_urls` API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the `is_global_host()` check on the initial URL.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `parse_urls` API method validates the initial URL hostname:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/api/__init__.py:600-604
if url:
    urlp = urlparse(url)
    hostname = urlp.hostname
    if urlp.scheme in (&amp;#34;http&amp;#34;, &amp;#34;https&amp;#34;) and hostname and is_global_host(hostname):
        page = get_url(url)
```&lt;/p&gt;
&lt;p&gt;`get_url()` is imported from `request_factory.py` and creates an `HTTPRequest` with default settings:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/request_factory.py:58-64
def get_url(self, *args, **kwargs):
    with HTTPRequest(None, self.get_options()) as h:
        rep = h.load(*args, **kwargs)
    return rep
```&lt;/p&gt;
&lt;p&gt;`HTTPRequest.__init__` sets `allow_private_ip = True` by default:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/http/http_request.py:75
self.allow_private_ip = True
```&lt;/p&gt;
&lt;p&gt;The `init_handle()` method enables redirect following:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/http/http_request.py:117-118
self.c.setopt(pycurl.FOLLOWLOCATION, 1)
self.c.setopt(pycurl.MAXREDIRS, 10)
```&lt;/p&gt;
&lt;p&gt;The `_pre_request_callback` that should block redirec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The SSRF mitigation added in commit `33c55da` for GHSA-7gvf-3w72-p2pg is incomplete. The `PREREQFUNCTION`-based private IP check was correctly applied to `HTTPChunk` (download path) but not to `HTTPRequest` (used by the `parse_urls` API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the `is_global_host()` check on the initial URL.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `parse_urls` API method validates the initial URL hostname:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/api/__init__.py:600-604
if url:
    urlp = urlparse(url)
    hostname = urlp.hostname
    if urlp.scheme in (&amp;#34;http&amp;#34;, &amp;#34;https&amp;#34;) and hostname and is_global_host(hostname):
        page = get_url(url)
```&lt;/p&gt;
&lt;p&gt;`get_url()` is imported from `request_factory.py` and creates an `HTTPRequest` with default settings:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/request_factory.py:58-64
def get_url(self, *args, **kwargs):
    with HTTPRequest(None, self.get_options()) as h:
        rep = h.load(*args, **kwargs)
    return rep
```&lt;/p&gt;
&lt;p&gt;`HTTPRequest.__init__` sets `allow_private_ip = True` by default:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/http/http_request.py:75
self.allow_private_ip = True
```&lt;/p&gt;
&lt;p&gt;The `init_handle()` method enables redirect following:&lt;/p&gt;
&lt;p&gt;```python
# src/pyload/core/network/http/http_request.py:117-118
self.c.setopt(pycurl.FOLLOWLOCATION, 1)
self.c.setopt(pycurl.MAXREDIRS, 10)
```&lt;/p&gt;
&lt;p&gt;The `_pre_request_callback` that should block redirec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2991</guid>
    </item>
  </channel>
</rss>
