vciy

CVEs we hold for Rsyncproject

Records whose assigning authority named Rsyncproject as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-70464rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake StallRsyncProject rsync
CVE-2026-70463rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive ParsingRsyncProject rsync
CVE-2026-70462rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUTRsyncProject rsync
CVE-2026-70461rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from EntryRsyncProject rsync
CVE-2026-70460rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir SymlinkRsyncProject rsync
CVE-2026-70459rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List EntryRsyncProject rsync
CVE-2026-70458rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED HandlingRsyncProject rsync
CVE-2026-70457rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()RsyncProject rsync
CVE-2026-70456rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()RsyncProject rsync
CVE-2026-70455rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread ExhaustionRsyncProject rsync
CVE-2026-70454rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL ModeRsyncProject rsync
CVE-2026-70453rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()RsyncProject rsync
CVE-2026-70452rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution FailureRsyncProject rsync
CVE-2026-53803rsync < 3.5.0 Symlink Following Arbitrary File OverwriteRsyncProject rsync
CVE-2026-53802rsync < 3.5.0 Arbitrary File Read via Symlink FollowingRsyncProject rsync
CVE-2026-53801rsync < 3.5.0 Symlink Race Condition Directory TraversalRsyncProject rsync
CVE-2026-53800rsync < 3.5.0 Symlink Race Condition via --remove-source-filesRsyncProject rsync
CVE-2026-53799rsync < 3.5.0 Symlink Race Condition via ACL/xattr ApplicationRsyncProject rsync
CVE-2026-53798rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mappingRsyncProject rsync
CVE-2026-53797rsync < 3.5.0 Symlink Race Condition Information DisclosureRsyncProject rsync
CVE-2026-53796rsync < 3.5.0 TOCTOU Race Condition via Destination Directory HandlingRsyncProject rsync
CVE-2026-53795rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-destRsyncProject rsync
CVE-2026-53794rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic ErrorRsyncProject rsync
CVE-2026-53793rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot ModeRsyncProject rsync
CVE-2026-53792rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum BlockRsyncProject rsync
CVE-2026-53791rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol HeaderRsyncProject rsync
CVE-2026-53790rsync < 3.5.0 Command Injection via Multiple Code PathsRsyncProject rsync
CVE-2026-53789rsync < 3.5.0 Arbitrary File Deletion via Malicious File ListRsyncProject rsync
CVE-2026-53788rsync < 3.5.0 Newline Injection via name-converter uid/gid mappingRsyncProject rsync
CVE-2026-53786rsync < 3.5.0 Filter Rule Bypass via --filter Merge DirectiveRsyncProject rsync
CVE-2026-53785rsync < 3.5.0 Path Traversal Write Escape via --relative ModeRsyncProject rsync
CVE-2026-53784rsync < 3.5.0 Path Traversal via Symlink Module RootRsyncProject rsync
CVE-2026-53783rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsyncRsyncProject rsync
CVE-2026-45232Rsync < 3.4.3 Off-by-One Stack Write via HTTP ProxyRsyncProject rsync
CVE-2026-43620Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()RsyncProject rsync
CVE-2026-43619Rsync < 3.4.3 Symlink Race Condition via Path-Based SyscallsRsyncProject rsync
CVE-2026-43618Rsync < 3.4.3 Integer Overflow Information DisclosureRsyncProject rsync
CVE-2026-43617Rsync < 3.4.3 Authorization Bypass via Hostname ResolutionRsyncProject rsync
CVE-2026-29518Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File WriteRsyncProject rsync

39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.