vciy

CVEs we hold for Rclone

Records whose assigning authority named Rclone as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-88046rclone: source object names can escape the configured root on uploadrclone
CVE-2026-88045rclone: S3 multipart declared-length memory exhaustionrclone
CVE-2026-88044rclone: RC per-server auth-proxy bypassrclone
CVE-2026-88018rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypassrclone
CVE-2026-88017rclone: FTP cross-session auth-proxy backend confusionrclone
CVE-2026-88016rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the…rclone
CVE-2026-88015rclone local: crafted Range request against a translated symlink panics (DoS)rclone
CVE-2026-88014rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespacerclone
CVE-2026-88013rclone: http backend forwards custom/auth headers to a different host on redirectrclone
CVE-2026-79783rclone before 1.74.4 Privilege Escalation via setuid Metadatarclone
CVE-2026-79782rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirectrclone
CVE-2026-79781rclone serve s3 Path Traversal via dot-dot object keysrclone
CVE-2026-79780rclone before v1.75.0 Credential Exposure via S3 Redirectrclone
CVE-2026-79779rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirectrclone
CVE-2026-79778rclone before v1.75.0 Denial of Service via TUS nil-response panicrclone
CVE-2026-79777rclone before v1.75.0 Information Disclosure via RC APIrclone
CVE-2026-79776rclone before 1.75.0 Authentication Bypass via pprofrclone
CVE-2026-79775rclone Archive Backend SquashFS Parser Denial of Servicerclone
CVE-2026-71313rclone: Local Encoding Path Traversalrclone
CVE-2026-71312rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Executionrclone
CVE-2026-71311rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlinesrclone
CVE-2026-71310rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memoryrclone
CVE-2026-71309rclone: Incomplete path validation allows backend root escape in serve resticrclone
CVE-2026-59733rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read…rclone
CVE-2026-59732rclone archive extract allows S3 destination prefix escape via crafted archive pathsrclone
CVE-2026-54572rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remoterclone
CVE-2026-49980Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing…rclone
CVE-2026-41179RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command executionrclone
CVE-2026-41176Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command executionrclone
CVE-2024-52522Rclone Improper Permission and Ownership Handling on Symlink Targets with --links and --metadatarclone

30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.