Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

GHSA-9Q47-3CM2-2RP8: GHSA-9Q47-3CM2-2RP8: Rate-Limit Bypass and Audit Log Spoofing in pyLoad WebUI

GHSA-9Q47-3CM2-2RP8: Rate-Limit Bypass and Audit Log Spoofing in pyLoad WebUI Vulnerability ID: GHSA-9Q47-3CM2-2RP8 CVSS Score: 6.5 Published: 2026-10-09 A critical security vulnerability has been identified and pat

GHSA-9Q47-3CM2-2RP8: Rate-Limit Bypass and Audit Log Spoofing in pyLoad WebUI

Vulnerability ID: GHSA-9Q47-3CM2-2RP8
CVSS Score: 6.5
Published: 2026-10-09

A critical security vulnerability has been identified and patched in the WebUI component of pyLoad, a popular Python-based open-source download manager. This vulnerability allows attackers to completely bypass API rate limits and spoof client IP addresses in audit logs due to unsafe parsing of the X-Forwarded-For HTTP header.

TL;DR

Unconditional trust of X-Forwarded-For headers in pyLoad allows remote attackers to bypass login rate limits and forge source IP addresses in audit logs.

Technical Details

  • CWE ID: CWE-348
  • Attack Vector: Network
  • CVSS: 6.5
  • Impact: Rate-Limit Bypass & Log Spoofing
  • Exploit Status: Proof of Concept
  • KEV Status: Not Listed

Affected Systems

  • pyLoad WebUI

Mitigation Strategies

  • Configure trusted_proxies configuration in default.cfg.
  • Deploy pyLoad behind a strict reverse proxy setup that overrides or filters incoming X-Forwarded-For headers from client connections.

Remediation Steps:

  1. Apply the security patch by running git pull or updating the container image.
  2. Set trusted_proxies under the webui config section to 0 if directly exposed, or to the exact number of upstream proxy hops.
  3. Verify that Click'N'Load loopback restrictions are intact by testing connections from non-local networks.

Read the full report for GHSA-9Q47-3CM2-2RP8 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.