github.com/rclone/rclone vulnerabilities
CVEs whose affected-version data names the github.com/rclone/rclone package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
32 CVEsRSS
CVE-2026-88014Medium· 6.3rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
CVE-2026-79779Medium· 5.3rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects
rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker obse…
CVE-2026-79782Low· 3.1rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request …
CVE-2026-79777Low· 2.7rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
CVE-2026-79783Low· 3.6rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservati…
CVE-2026-79781Medium· 6.5rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys
rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-sec…
CVE-2026-79780Medium· 5.3rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted …
CVE-2026-79778Medium· 5.3rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors
rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connectio…
GO-2026-6197NoneWebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
GO-2026-6196NoneS3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
GO-2026-6190NoneUnsafe file permission restoration from metadata in github.com/rclone/rclone
Unsafe file permission restoration from metadata in github.com/rclone/rclone
GO-2026-6189NonePath traversal in serve s3 in github.com/rclone/rclone
Path traversal in serve s3 in github.com/rclone/rclone
GO-2026-6188NoneS3 redirect sanitization omits sensitive headers in github.com/rclone/rclone
S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone
GO-2026-6183NoneNil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone
Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone
GO-2026-6181NoneVerbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
GHSA-gwfq-86j8-7qhvLow· 2.7rclone: Verbose Stack Trace Disclosure in RC API Error Responses
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
GHSA-945v-v9p3-v5xwLow· 3.6rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
CVE-2026-71309Highrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic…
CVE-2026-54572High· 7.5rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
CVE-2026-71310Medium· 5.9rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over…
GHSA-3x6r-wxxg-53vvMedium· 5.3rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
GHSA-8v25-v8p6-qf7vMedium· 6.5rclone: Path traversal in serve s3 allows reading and overwriting root-level files
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
GHSA-8mxv-9xhp-86h4Medium· 5.3rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
CVE-2026-71311Medium· 6.4rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately before an…
GHSA-h4mf-4v27-hggjMedium· 5.3rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
CVE-2026-71312High· 8.0rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscap…
CVE-2026-59733High· 8.8rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
GHSA-gx4c-2hqx-cw2rLow· 3.1rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
CVE-2026-59732Medium· 5.0rclone archive extract allows S3 destination prefix escape via crafted archive paths
rclone archive extract allows S3 destination prefix escape via crafted archive paths
CVE-2026-71313Medium· 6.9rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent …