All verified exploits

CVE-2026-35459 SSRF Filter Bypass via HTTP Redirect

Deterministic critical pyLoad Added cve-verified-cve-2026-35459

Detects pyLoad instances through version 0.5.0b3.dev96 where the download engine's SSRF filter only validates the initial URL hostname. An authenticated attacker can submit a download URL pointing to an attacker-controlled server that responds with a 302 redirect to internal endpoints (cloud metadata at 169.254.169.254, localhost services, private network). pycurl follows the redirect without any destination validation, exposing IAM credentials and internal services. The fix adds a pycurl PREREQFUNCTION callback that checks every connection including redirects.

Is your app exploitable through CVE-2026-35459?

Scan your domain free