DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-R44W-V6GF-X3P6: Authentication Bypass in pyLoad API Key Caching Mechanism (GHSA-R44W-V6GF-X3P6)

Authentication Bypass in pyLoad API Key Caching Mechanism (GHSA-R44W-V6GF-X3P6)

Vulnerability ID: GHSA-R44W-V6GF-X3P6
CVSS Score: 8.1
Published: 2026-10-09

An authentication bypass vulnerability in pyLoad allows unauthenticated remote attackers to gain administrative API access. The vulnerability is caused by a logical flaw in the API key cache validation lookup, where authentication states are cached using only the public key identifier, skipping cryptographic token verification on cache hits.

TL;DR

Remote attackers can bypass authentication in pyLoad and access administrative API endpoints by exploiting a logical flaw that caches authentication states using public key IDs instead of the private secret token.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-287
  • Attack Vector: Network
  • CVSS v3.1 Score: 8.1
  • Exploit Status: poc
  • KEV Status: Not Listed
  • Affected Package: pyload-ng

Affected Systems

  • pyLoad (pyload-ng)
  • pyload-ng: < 0.5.0b3.dev101 (Fixed in: 0.5.0b3.dev101)

Code Analysis

Commit: 00d1372

Fix security vulnerability in apikey cache validation

@@ -150,7 +150,7 @@ def __init__(self, core):
         self._ = core._

         # API key cache
-        self._apikey_cache = {}  # Format: {key_id: (timestamp, data)}
+        self._apikey_cache = {}  # Format: {apikey: (timestamp, data)}
Enter fullscreen mode Exit fullscreen mode

Mitigation Strategies

  • Upgrade pyload-ng to version 0.5.0b3.dev101 or higher immediately.
  • Restrict access to the pyLoad API endpoints (/api/) to authorized network CIDRs via local firewalls or reverse proxy configuration.
  • Deploy external web application firewall (WAF) rules or reverse proxy authentication to intercept programmatic calls.

Remediation Steps:

  1. Identify running containerized or localized instances of pyLoad.
  2. Run 'pip install --upgrade pyload-ng' to pull the latest security release.
  3. Verify the installed version is 0.5.0b3.dev101 or later.
  4. Restart the pyload daemon to purge active insecure caches.

References


Read the full report for GHSA-R44W-V6GF-X3P6 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)