Reliance on Cookies without Validation and Integrity Checking Affecting yt-dlp package, versions [2023.9.24, 2026.6.9)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.27% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-YTDLP-17353908
  • published17 Jun 2026
  • disclosed16 Jun 2026
  • creditsepro

Introduced: 16 Jun 2026

CVE-2026-50019  (opens in a new tab)
CWE-565  (opens in a new tab)

How to fix?

Upgrade yt-dlp to version 2026.6.9 or higher.

Overview

yt-dlp is an A youtube-dl fork with additional features and patches

Affected versions of this package are vulnerable to Reliance on Cookies without Validation and Integrity Checking via curl. An attacker can obtain sensitive cookie information by crafting a malicious website that embeds a specially crafted URL, causing cookies to be sent to unintended hosts during HTTP redirects or when download fragment hosts differ from their parent manifest's.

Workaround

This vulnerability can be mitigated by not using the --downloader curl option.

CVSS Base Scores

version 4.0
version 3.1