CVE-2026-44226Pyload · Pyload
Vulnerability data via NVD (ingested)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<path:filename> is reachable without authentication and renders attacker-controlled template names, an unauthenticated user can reliably trigger a server exception (for example by requesting a non-existent template) and receive internal stack traces in the HTTP response. This vulnerability is fixed in 0.5.0b3.dev100.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-44226product:"Pyload Pyload"http.html:"Pyload"More intel sources (5)
vuln:CVE-2026-44226vulnerabilities.cve_id: CVE-2026-44226CVE-2026-44226CVE-2026-44226"CVE-2026-44226" exploit -site:nvd.nist.gov