All verified exploits

CVE-2026-33511 ClickNLoad Localhost Bypass via Forged Host Header

Deterministic critical pyLoad Added cve-verified-cve-2026-33511

Detects pyLoad instances before version 0.5.0b3.dev97 where the ClickNLoad localhost restriction can be bypassed by forging the HTTP Host header to 127.0.0.1:9666. This allows unauthenticated remote access to download injection, file write, and JavaScript execution endpoints. The fix replaces the string-based Host header check with proper is_loopback_request() validation.

Is your app exploitable through CVE-2026-33511?

Scan your domain free