VulnSea

rsync vulnerabilities

CVEs whose affected-version data names the rsync package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-43618High· 8.1
4mo ago

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receive…

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receive…

Twilightsamba · rsyncEPSS 0.78%via NVD
CVE-2026-29518High· 7.0
4mo ago

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with s…

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with s…

Twilightsamba · rsyncEPSS 0.15%via NVD
CVE-2026-41035High· 7.4
5mo ago

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configuratio…

Twilightsamba · rsyncEPSS 0.39%via NVD
CVE-2024-12084Critical· 9.8PoC
1y ago

A heap-based buffer overflow flaw was found in the rsync daemon

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attac…

Abyssalsamba · rsyncEPSS 72%via NVD
CVE-2024-12088Medium· 6.5
1y ago

A flaw was found in rsync

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vul…

Sunlitsamba · rsyncEPSS 4.7%via NVD
CVE-2024-12087Medium· 6.5
1y ago

A path traversal vulnerability exists in rsync

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the clien…

Sunlitsamba · rsyncEPSS 2.3%via NVD
CVE-2024-12086Medium· 6.1
1y ago

A flaw was found in rsync

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server w…

Sunlitsamba · rsyncEPSS 1.8%via NVD
CVE-2024-12085High· 7.5PoC
1y ago

A flaw was found in rsync which could be triggered when rsync compares file checksums

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak o…

Midnightsamba · rsyncEPSS 8.8%via NVD
rsync vulnerabilities (CVEs) · VulnSea