rclone
Consumer Softwareoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting rclone.
- CVE-2026-79782rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect3.1
- CVE-2026-79783rclone before 1.74.4 Privilege Escalation via setuid Metadata3.6
- CVE-2026-79781rclone serve s3 Path Traversal via dot-dot object keys6.5
- CVE-2026-79779rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect5.3
- CVE-2026-79780rclone before v1.75.0 Credential Exposure via S3 Redirect5.3
- CVE-2026-79778rclone before v1.75.0 Denial of Service via TUS nil-response panic5.3
- CVE-2026-79777rclone before v1.75.0 Information Disclosure via RC API2.7
- CVE-2026-79776rclone before 1.75.0 Authentication Bypass via pprof5.3
- CVE-2026-79775rclone Archive Backend SquashFS Parser Denial of Service6.5
- CVE-2026-71313rclone: Local Encoding Path Traversal6.9
- CVE-2026-71312rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution8.0
- CVE-2026-71311rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines6.4
- CVE-2026-71310rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory5.9
- CVE-2026-59733rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories8.8
- CVE-2026-54572rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote7.5