CVE-2026-33992 is a Server-Side Request Forgery (SSRF) vulnerability affecting pyLoad versions prior to 0.5.0b3.dev97, caused by its download engine accepting arbitrary URLs without validation. An authenticated attacker can exploit this flaw (CVSS 6.5 MEDIUM) to access internal network services and exfiltrate sensitive cloud provider metadata, including DigitalOcean droplet IDs and SSH keys. There is currently no evidence of active exploitation, nor are public exploit modules or proof-of-concept code available. Community discussion is minimal, with only one recent mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.5.0CPE matchmatch criteria | cpe:2.3:a:pyload:pyload:0.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.