QSearchQSearch

CVE-2026-44226

5.3 MEDIUM

pyLoad is a free and open-source download manager written in Python

Published: 2026-05-11 · Last updated: 2026-05-18

Severity and scoring

CVSS
5.3 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE
CWE-209

Affected products

VendorProduct
pyloadpyload

Description

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<path:filename> is reachable without authentication and renders attacker-controlled template names, an unauthenticated user can reliably trigger a server exception (for example by requesting a non-existent template) and receive internal stack traces in the HTTP response. This vulnerability is fixed in 0.5.0b3.dev100.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-47248 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
  • CVE-2026-40997 Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semant... (5.3 MEDIUM)
  • CVE-2026-41730 Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer intern... (5.3 MEDIUM)
  • CVE-2025-52611 HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability (3.1 LOW)
  • CVE-2025-52606 HCL iControl was affected by Weak Input Validation vulnerability (4.3 MEDIUM)