rclone has 44 CVEs on record. Disclosure cadence is accelerating: 41 in the last 90 days against 3 in the 90 before. The busiest recent month was August 2026 with 30. The median CVSS is 5.3 (medium), with 5 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-22 (9) and CWE-319 (6). Most affected products: github.com/rclone/rclone (31), rclone (13).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 41 prev 3
Products
- github.com/rclone/rclone 31
- rclone 13
Worst active — by depth score
CVE-2026-41176Critical· 9.8Rclone is a command-line program to sync files and directories to and from different cloud storage providers67CVE-2026-41179Critical· 9.8RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution67CVE-2026-88018Critical· 9.8rclone is a command-line program to sync files and directories to and from different cloud storage providers66CVE-2026-88044Critical· 9.1rclone is a command-line program to sync files and directories to and from different cloud storage providers62CVE-2026-49980Critical· 9.8Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix54
rclone vulnerabilities
CVEs affecting rclone, newest first. Open any entry for full detail, references, and exploit status.
44 CVEsRSS
CVE-2026-71310Medium· 5.9rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over…
GHSA-3x6r-wxxg-53vvMedium· 5.3rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
GHSA-8v25-v8p6-qf7vMedium· 6.5rclone: Path traversal in serve s3 allows reading and overwriting root-level files
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
GHSA-8mxv-9xhp-86h4Medium· 5.3rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
CVE-2026-71311Medium· 6.4rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately before an…
GHSA-h4mf-4v27-hggjMedium· 5.3rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
CVE-2026-71312High· 8.0rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscap…
CVE-2026-59733High· 8.8rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
GHSA-gx4c-2hqx-cw2rLow· 3.1rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
CVE-2026-59732Medium· 5.0rclone archive extract allows S3 destination prefix escape via crafted archive paths
rclone archive extract allows S3 destination prefix escape via crafted archive paths
CVE-2026-71313Medium· 6.9rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent …
CVE-2026-49980Critical· 9.8Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
CVE-2026-41176Critical· 9.8PoCRclone is a command-line program to sync files and directories to and from different cloud storage providers
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, includin…
CVE-2026-41179Critical· 9.8PoCRClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution