Impact
The vulnerability is a boundary‑checking flaw in pyLoad’s SSRF guard that allows a low‑privileged user to supply an IPv6 literal containing a 6to4 or NAT64 transition wrapper. The guard relies on Python’s global‑address classification without inspecting the embedded IPv4 destination, so the fake IPv6 address can resolve to a loopback, private, CGNAT, or link‑local IPv4 address. Successful exploitation permits internal‑network reconnaissance, timing‑based confirmation, limited service disruption, or cloud metadata disclosure when the wrapped address is routable to internal resources.
Affected Systems
The flaw affects the pyLoad download manager on versions prior to 0.5.0b3.dev101, running with Python 3.9 through 3.11, and when the host participates in 6to4 or NAT64 transition routing.
Risk and Exploitability
With a CVSS score of 4.9 the vulnerability is a medium severity issue; its EPSS score is not available and it is not listed in KEV. The vulnerability can be exploited through crafted URL input or curl requests that trigger the vulnerable guard; it requires the pyLoad host to route 6to4 or NAT64 traffic, but does not need elevated privileges.
OpenCVE Enrichment
Github GHSA