GHSA-9Q47-3CM2-2RP8: GHSA-9Q47-3CM2-2RP8: Rate-Limit Bypass and Audit Log Spoofing in pyLoad WebUI
GHSA-9Q47-3CM2-2RP8: Rate-Limit Bypass and Audit Log Spoofing in pyLoad WebUI Vulnerability ID: GHSA-9Q47-3CM2-2RP8 CVSS Score: 6.5 Published: 2026-10-09 A critical security vulnerability has been identified and pat
GHSA-9Q47-3CM2-2RP8: Rate-Limit Bypass and Audit Log Spoofing in pyLoad WebUI
Vulnerability ID: GHSA-9Q47-3CM2-2RP8
CVSS Score: 6.5
Published: 2026-10-09
A critical security vulnerability has been identified and patched in the WebUI component of pyLoad, a popular Python-based open-source download manager. This vulnerability allows attackers to completely bypass API rate limits and spoof client IP addresses in audit logs due to unsafe parsing of the X-Forwarded-For HTTP header.
TL;DR
Unconditional trust of X-Forwarded-For headers in pyLoad allows remote attackers to bypass login rate limits and forge source IP addresses in audit logs.
Technical Details
- CWE ID: CWE-348
- Attack Vector: Network
- CVSS: 6.5
- Impact: Rate-Limit Bypass & Log Spoofing
- Exploit Status: Proof of Concept
- KEV Status: Not Listed
Affected Systems
- pyLoad WebUI
Mitigation Strategies
- Configure trusted_proxies configuration in default.cfg.
- Deploy pyLoad behind a strict reverse proxy setup that overrides or filters incoming X-Forwarded-For headers from client connections.
Remediation Steps:
- Apply the security patch by running git pull or updating the container image.
- Set trusted_proxies under the webui config section to 0 if directly exposed, or to the exact number of upstream proxy hops.
- Verify that Click'N'Load loopback restrictions are intact by testing connections from non-local networks.
Read the full report for GHSA-9Q47-3CM2-2RP8 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.