highCVSS 8.1Vulnerability

GHSA-r44w-v6gf-x3p6

## Summary The API-key cache in `check_apikey()` allows an attacker to authenticate with a **forged API key** as long as the legitimate key for the same `key_id` has been used recently. On a cache hit, the API key **secret is never verified**, resulting in a complete authentication bypass during the cache lifetime. --- # Affected Components - `src/pyload/core/api/init.py` - `Api.check_apikey()` - `src/pyload/core/database/apikey_database.py` - `check_apikey()` - `_check_key()` The cache is used by normal API requests through: - `src/pyload/webui/app/helpers.py` which calls: ```python api.check_apikey(api_key) ``` without providing a `ttl`, meaning the default **300-second cache** is always enabled. --- # Root Cause Successful API key validations are cached in: ```python self._apikey_cache ``` using the following structure: ```python { key_id: (timestamp, cached_data) } ``` The cache key is based **only on `key_id`**, and that value is parsed directly from the user-supplied API key rather than being obtained from a trusted lookup. When a cache hit occurs within the TTL, `check_apikey()` returns: ```python { "success": True, "data": cached_data } ``` after checking only: - `expires_at` At no point on this execution path is the supplied secret: ```text apikey[-43:] ``` compared against the stored key hash. --- The actual secret verification exists only in: ```python _check_key() ``` which correctly uses: ```python hmac.compare_digest() ``` However, this function is only reached on a **cache miss** through the database layer's `check_apikey()` implementation. Furthermore, the cached object cannot be used for verification because it intentionally does **not** include the stored key hash. The cached record contains only: - `id` - `user_id` - `name` - `created_at` - `expires_at` - `last_used` Since `key_hash` is absent, the cache lacks the information required to validate the presented secret. As a result, once a legiti

Properties

summary
pyLoad has an authentication bypass in API key validation (check_apikey cache)
severity
high
cvss_score
8.1
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T16:43:55Z
source_url
https://github.com/advisories/GHSA-r44w-v6gf-x3p6
ghsa_updated
2026-10-09T16:43:56Z
ghsa_id
GHSA-r44w-v6gf-x3p6
last_source
GitHub Advisory Database
cve_id
GHSA-r44w-v6gf-x3p6
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
true

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Improper Authentication

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/pyload-ng

AFFECTS (1)

→[Software]pip/pyload-ng

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-r44w-v6gf-x3p6 (CVSS 8.1) — Ninja Signal Threat Intelligence | Ninja Signal