Authentication Bypass in pyLoad API Key Caching Mechanism (GHSA-R44W-V6GF-X3P6)
Vulnerability ID: GHSA-R44W-V6GF-X3P6
CVSS Score: 8.1
Published: 2026-10-09
An authentication bypass vulnerability in pyLoad allows unauthenticated remote attackers to gain administrative API access. The vulnerability is caused by a logical flaw in the API key cache validation lookup, where authentication states are cached using only the public key identifier, skipping cryptographic token verification on cache hits.
TL;DR
Remote attackers can bypass authentication in pyLoad and access administrative API endpoints by exploiting a logical flaw that caches authentication states using public key IDs instead of the private secret token.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-287
- Attack Vector: Network
- CVSS v3.1 Score: 8.1
- Exploit Status: poc
- KEV Status: Not Listed
- Affected Package: pyload-ng
Affected Systems
- pyLoad (pyload-ng)
-
pyload-ng: < 0.5.0b3.dev101 (Fixed in:
0.5.0b3.dev101)
Code Analysis
Commit: 00d1372
Fix security vulnerability in apikey cache validation
@@ -150,7 +150,7 @@ def __init__(self, core):
self._ = core._
# API key cache
- self._apikey_cache = {} # Format: {key_id: (timestamp, data)}
+ self._apikey_cache = {} # Format: {apikey: (timestamp, data)}
Mitigation Strategies
- Upgrade pyload-ng to version 0.5.0b3.dev101 or higher immediately.
- Restrict access to the pyLoad API endpoints (/api/) to authorized network CIDRs via local firewalls or reverse proxy configuration.
- Deploy external web application firewall (WAF) rules or reverse proxy authentication to intercept programmatic calls.
Remediation Steps:
- Identify running containerized or localized instances of pyLoad.
- Run 'pip install --upgrade pyload-ng' to pull the latest security release.
- Verify the installed version is 0.5.0b3.dev101 or later.
- Restart the pyload daemon to purge active insecure caches.
References
Read the full report for GHSA-R44W-V6GF-X3P6 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)