<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Pyload-Ng (&gt;= 0.5.0b3.dev1, &lt;= 0.5.0b3.dev101) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pyload-ng--0.5.0b3.dev1--0.5.0b3.dev101/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 21:25:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pyload-ng--0.5.0b3.dev1--0.5.0b3.dev101/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass and Brute-Force Oracle in pyload-ng</title><link>https://feed.craftedsignal.io/briefs/2026-10-pyload-auth-bypass/</link><pubDate>Fri, 09 Oct 2026 21:25:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-pyload-auth-bypass/</guid><description>An insecure permission check in the pyload-ng API allows any authenticated user to perform administrative password brute-forcing via a side-channel oracle.</description><content:encoded><![CDATA[<p>Research has identified a critical vulnerability in pyload-ng (versions 0.5.0b3.dev1 through 0.5.0b3.dev101) originating from an incorrectly implemented permission gate. The <code>Api.getUserData</code> and <code>Api.get_userdata</code> endpoints are decorated with <code>@permission(Perms.ANY)</code>. In the pyload-ng codebase, <code>Perms.ANY</code> is defined as <code>0</code>, and the permission validation logic uses a bitmask AND operation. Consequently, any authenticated session, regardless of privileges, satisfies the <code>has_permission</code> check. These endpoints act as thin wrappers around the internal <code>check_auth</code> method, which is intended to be restricted to administrators. By passing an arbitrary password to these endpoints, an attacker can determine if the password is valid based on the API response, creating a high-speed brute-force oracle. This vulnerability is significantly amplified by the lack of account lockout mechanisms and a flaw in the rate-limiting implementation that permits bypassing by rotating the <code>X-Forwarded-For</code> HTTP header.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains access to a low-privileged account on a pyload-ng instance (e.g., <code>role=USER</code>, <code>permission=0</code>).</li>
<li>Attacker initiates an authenticated session using their own credentials.</li>
<li>Attacker identifies the target administrative account (e.g., 'pyload').</li>
<li>Attacker constructs a script to iterate through password guesses using the <code>/api/getUserData</code> endpoint.</li>
<li>For each attempt, the attacker modifies the <code>X-Forwarded-For</code> header to bypass the 100 req/min rate limit bucket.</li>
<li>Attacker monitors the HTTP response: a <code>200 OK</code> with null data indicates an incorrect password, while a <code>200 OK</code> with user details confirms successful authentication.</li>
<li>Upon identifying the correct password, the attacker authenticates as the administrator via the <code>/login</code> endpoint.</li>
<li>Attacker uses administrative privileges to exfiltrate all user data or perform other unauthorized actions.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full administrative takeover of the pyload-ng instance. An attacker can recover the administrator's password via automated brute force, as there are no failed-login throttles or account lockout policies. Once the admin account is compromised, the attacker gains complete control over the application, including the ability to dump sensitive user data and credentials stored in the system.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to a patched version of pyload-ng as soon as a fix is available, or remove the vulnerable <code>getUserData</code> and <code>get_userdata</code> methods if they are not required.</li>
<li>Implement strict ingress filtering for web traffic to ensure that the <code>X-Forwarded-For</code> header is only trusted when originating from a validated, internal proxy.</li>
<li>Configure the web server to use the real client IP address for rate-limiting calculations instead of trusting client-supplied headers.</li>
<li>Apply granular rate limiting or account lockout policies to mitigate automated brute-force attempts.</li>
<li>Enable account-level monitoring for unusual spikes in failed authentication attempts directed at administrative accounts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>credential-access</category><category>authentication-bypass</category><category>web-application</category></item></channel></rss>