{"id":"CVE-2023-0227","aliases":["GHSA-rv9x-wmw4-44qj","PYSEC-2026-906"],"title":"Pyload Insufficient Session Expiration vulnerability","summary":"Pyload Insufficient Session Expiration vulnerability","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","vendor":"pyload-ng","product":"pyload-ng","ecosystem":"pip","affected":["pyload-ng < 0.5.0b3.dev36"],"patched":["pyload-ng 0.5.0b3.dev36"],"published":"2023-01-12","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-rv9x-wmw4-44qj","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0227"},{"url":"https://github.com/pyload/pyload/commit/c035714c0596b704b11af0f8a669352f128ad2d9"},{"url":"https://github.com/pyload/pyload"},{"url":"https://huntr.dev/bounties/af3101d7-fea6-463a-b7e4-a48be219e31b"}],"tags":["osv","pip"],"epss":0.00655,"epssPercentile":0.49981,"ingestedAt":"2026-07-08T18:25:53.026Z","slug":"CVE-2023-0227","body":"## Overview\n\nPyload 0.5.0b3.dev35 has an Insufficient Session Expiration vulnerability. A patch is available and anticipated to be part of version 0.5.0b3.dev36.\n\n## Affected packages\n\n- `pyload-ng < 0.5.0b3.dev36`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pyload-ng 0.5.0b3.dev36`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}