Detects pyLoad instances through version 0.5.0b3.dev96 where the download engine's SSRF filter only validates the initial URL hostname. An authenticated attacker can submit a download URL pointing to an attacker-controlled server that responds with a 302 redirect to internal endpoints (cloud metadata at 169.254.169.254, localhost services, private network). pycurl follows the redirect without any destination validation, exposing IAM credentials and internal services. The fix adds a pycurl PREREQFUNCTION callback that checks every connection including redirects.
Is your app exploitable through CVE-2026-35459?
Scan your domain free