CVE-2026-88013
- EPSS 0.18%
- Veröffentlicht 10.09.2026 15:39:56
- Zuletzt bearbeitet 23.09.2026 20:28:10
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backend/http/http.g...
CVE-2026-79783
- EPSS 0.14%
- Veröffentlicht 25.08.2026 15:16:11
- Zuletzt bearbeitet 10.09.2026 20:46:19
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an un...
CVE-2026-79782
- EPSS 0.13%
- Veröffentlicht 25.08.2026 15:16:11
- Zuletzt bearbeitet 10.09.2026 20:46:19
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.
CVE-2026-79781
- EPSS 0.26%
- Veröffentlicht 25.08.2026 15:16:10
- Zuletzt bearbeitet 10.09.2026 20:46:19
rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-secret.txt to es...
- EPSS 0.1%
- Veröffentlicht 25.08.2026 15:16:09
- Zuletzt bearbeitet 10.09.2026 20:46:19
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted endpoint can ...
- EPSS 0.11%
- Veröffentlicht 25.08.2026 15:16:09
- Zuletzt bearbeitet 10.09.2026 20:46:19
rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the pla...
- EPSS 0.23%
- Veröffentlicht 25.08.2026 15:16:08
- Zuletzt bearbeitet 10.09.2026 20:46:19
rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS...
CVE-2026-79777
- EPSS 0.24%
- Veröffentlicht 25.08.2026 15:16:07
- Zuletzt bearbeitet 10.09.2026 20:46:19
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
CVE-2026-79776
- EPSS 0.3%
- Veröffentlicht 25.08.2026 15:16:07
- Zuletzt bearbeitet 10.09.2026 20:46:19
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv i...
CVE-2026-79775
- EPSS 0.31%
- Veröffentlicht 25.08.2026 15:16:06
- Zuletzt bearbeitet 10.09.2026 20:46:19
rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacke...