GHSA-9q47-3cm2-2rp8
## Summary pyLoad determines the "client IP" used for its rate-limiting decorator and for its security/audit logging by reading the client-supplied `X-Forwarded-For` (XFF) HTTP header and taking the leftmost value. No trusted-proxy configuration exists (the Cheroot WSGI server faces clients directly, and there is no `ProxyFix` middleware). Because any client can freely set this header, an attacker can (1) completely bypass rate limiting by rotating the header on each request, and (2) forge the source IP recorded in security logs for login and API-key authentication failures, defeating IP-based blocking (e.g. fail2ban) and poisoning attribution. ## Severity Medium — CVSS 3.1: `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L` (~5.3) - CWE-807: Reliance on Untrusted Inputs in a Security Decision - CWE-290: Authentication Bypass by Spoofing - CWE-348: Use of Less Trusted Source ## Affected Version pyLoad 0.5.0b3 (built from the `develop` branch). Confirmed still present and exploitable in the later `pyload-develop-2` snapshot (the affected files are byte-identical between the two; the `develop-2` changes only touched the unrelated API-key cache). ## Affected Component Web UI request handling — client-IP derivation used by rate limiting and security logging. - `src/pyload/webui/app/helpers.py:446` — inside the `rate_limit()` decorator; derives the per-IP bucket key. - `src/pyload/webui/app/helpers.py:357` — API-key authentication success/failure logging. - `src/pyload/webui/app/blueprints/app_blueprint.py:81` — web login success/failure logging. - `src/pyload/webui/webserver_thread.py` — Cheroot serves the Flask app directly; no reverse-proxy trust boundary or `ProxyFix`. - Consumer: `src/pyload/webui/app/blueprints/api_blueprint.py:25` applies `@rate_limit(count=100, period=60)` to the `/api/<func>` RPC endpoint. ## Description: All three locations derive the client IP with the identical expression: ```python client_ip = flask.request.headers.get("X-Forwarded-
Properties
- ghsa_id
- GHSA-9q47-3cm2-2rp8
- severity
- medium
- summary
- pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-9q47-3cm2-2rp8
- signal_observed_at
- 2026-10-10T02:17:04+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-10-10T02:17:04+00:00
- ghsa_published
- 2026-10-09T17:09:12Z
- source_url
- https://github.com/advisories/GHSA-9q47-3cm2-2rp8
- ghsa_updated
- 2026-10-09T17:09:14Z
Related Entities (4)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph