GO-2026-6196None▾ SunlitS3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
github.com/rclone/rclone < 1.74.4Upgrade to a patched release:
github.com/rclone/rclone 1.74.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79782Low· 3.1rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host
GHSA-gx4c-2hqx-cw2rLow· 3.1rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
CVE-2026-79783Low· 3.6rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files
CVE-2026-79781Medium· 6.5rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys
GO-2026-6190NoneUnsafe file permission restoration from metadata in github.com/rclone/rclone
GO-2026-6189NonePath traversal in serve s3 in github.com/rclone/rclone