Rsync
This hub aggregates every CVE we track for Rsync, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
35
CVEs tracked
7
Critical
11
High
0
In CISA KEV
Severity distribution
MEDIUM13HIGH11CRITICAL7LOW4
Monthly trend
0
0
0
0
0
0
6
0
0
0
0
0
0
0
0
0
1
0
0
0
0
1
6
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Rsync.
- CVE-2026-29518Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write7.0
- CVE-2026-43617Rsync < 3.4.3 Authorization Bypass via Hostname Resolution4.8
- CVE-2026-43618Rsync < 3.4.3 Integer Overflow Information Disclosure8.1
- CVE-2026-43619Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls6.3
- CVE-2026-43620Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()6.5
- CVE-2026-45232Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy3.1
- CVE-2026-41035In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux...7.4
- CVE-2025-10158Rsync: Out of bounds array access via negative index4.3
- CVE-2024-12084Rsync: heap buffer overflow in rsync due to improper checksum length handling9.8
- CVE-2024-12087Rsync: path traversal vulnerability in rsync6.5
- CVE-2024-12747Rsync: race condition in rsync handling symbolic links5.6
- CVE-2024-12088Rsync: --safe-links option bypass leads to path traversal6.5
- CVE-2024-12086Rsync: rsync server leaks arbitrary client files6.1
- CVE-2024-12085Rsync: info leak via uninitialized stack contents7.5
- CVE-2022-29154An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories ar...7.4
Product normalization is registry-driven with AI assist and human review. How it works