{"id":"CVE-2026-79779","title":"rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects","summary":"rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker obse…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-319"],"vendor":"rclone","product":"github.com/rclone/rclone","affected":["github.com/rclone/rclone < 1.75.0"],"patched":["github.com/rclone/rclone 1.75.0"],"published":"2026-08-25","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:46:19.780","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79779","references":[{"url":"https://github.com/rclone/rclone/security/advisories/GHSA-h4mf-4v27-hggj","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/rclone-before-webdav-credential-exposure-via-https-to-http-redirect","label":"disclosure@vulncheck.com"},{"url":"https://github.com/rclone/rclone/commit/59b513b0e74fd2943ccbb8891d5ce00f860e6d26"},{"url":"https://github.com/rclone/rclone"},{"url":"https://github.com/rclone/rclone/releases/tag/v1.75.0"}],"tags":["nvd","osv","go"],"epss":0.00108,"epssPercentile":0.01345,"aliases":["GHSA-h4mf-4v27-hggj","GO-2026-6197"],"ecosystem":"go","ingestedAt":"2026-08-27T19:27:47.257Z","slug":"CVE-2026-79779","body":"## Overview\n\nrclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and reuse credentials to perform WebDAV operations with the compromised account's permissions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-79779)\n\nAffected packages:\n\n- `github.com/rclone/rclone < 1.75.0`\n\nPatched in:\n\n- `github.com/rclone/rclone 1.75.0`\n\nSource: https://osv.dev/vulnerability/GHSA-h4mf-4v27-hggj","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}