mediumVulnerability

GHSA-9q47-3cm2-2rp8

## Summary pyLoad determines the "client IP" used for its rate-limiting decorator and for its security/audit logging by reading the client-supplied `X-Forwarded-For` (XFF) HTTP header and taking the leftmost value. No trusted-proxy configuration exists (the Cheroot WSGI server faces clients directly, and there is no `ProxyFix` middleware). Because any client can freely set this header, an attacker can (1) completely bypass rate limiting by rotating the header on each request, and (2) forge the source IP recorded in security logs for login and API-key authentication failures, defeating IP-based blocking (e.g. fail2ban) and poisoning attribution. ## Severity Medium — CVSS 3.1: `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L` (~5.3) - CWE-807: Reliance on Untrusted Inputs in a Security Decision - CWE-290: Authentication Bypass by Spoofing - CWE-348: Use of Less Trusted Source ## Affected Version pyLoad 0.5.0b3 (built from the `develop` branch). Confirmed still present and exploitable in the later `pyload-develop-2` snapshot (the affected files are byte-identical between the two; the `develop-2` changes only touched the unrelated API-key cache). ## Affected Component Web UI request handling — client-IP derivation used by rate limiting and security logging. - `src/pyload/webui/app/helpers.py:446` — inside the `rate_limit()` decorator; derives the per-IP bucket key. - `src/pyload/webui/app/helpers.py:357` — API-key authentication success/failure logging. - `src/pyload/webui/app/blueprints/app_blueprint.py:81` — web login success/failure logging. - `src/pyload/webui/webserver_thread.py` — Cheroot serves the Flask app directly; no reverse-proxy trust boundary or `ProxyFix`. - Consumer: `src/pyload/webui/app/blueprints/api_blueprint.py:25` applies `@rate_limit(count=100, period=60)` to the `/api/<func>` RPC endpoint. ## Description: All three locations derive the client IP with the identical expression: ```python client_ip = flask.request.headers.get("X-Forwarded-

Properties

ghsa_id
GHSA-9q47-3cm2-2rp8
severity
medium
summary
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header
last_source
GitHub Advisory Database
cve_id
GHSA-9q47-3cm2-2rp8
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
true
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T17:09:12Z
source_url
https://github.com/advisories/GHSA-9q47-3cm2-2rp8
ghsa_updated
2026-10-09T17:09:14Z

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Authentication Bypass by Spoofing

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/pyload-ng

AFFECTS (1)

→[Software]pip/pyload-ng

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-9q47-3cm2-2rp8 — Ninja Signal Threat Intelligence | Ninja Signal