VulnSea

rclone has 44 CVEs on record. Disclosure cadence is accelerating: 41 in the last 90 days against 3 in the 90 before. The busiest recent month was August 2026 with 30. The median CVSS is 5.3 (medium), with 5 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-22 (9) and CWE-319 (6). Most affected products: github.com/rclone/rclone (31), rclone (13).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.3
Publish → KEV
—
Last 90 days
41 prev 3

Products

  • github.com/rclone/rclone 31
  • rclone 13
44
Total CVEs
5
Critical
0
CISA KEV
0
Exploited

rclone vulnerabilities

CVEs affecting rclone, newest first. Open any entry for full detail, references, and exploit status.

44 CVEsRSS

CVE-2026-71310Medium· 5.9
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.61%via NVD
GHSA-3x6r-wxxg-53vvMedium· 5.3
1mo ago

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
GHSA-8v25-v8p6-qf7vMedium· 6.5
1mo ago

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
GHSA-8mxv-9xhp-86h4Medium· 5.3
1mo ago

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-71311Medium· 6.4
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately before an…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.39%via NVD
GHSA-h4mf-4v27-hggjMedium· 5.3
1mo ago

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-71312High· 8.0
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscap…

▾ Twilightrclone · github.com/rclone/rcloneEPSS 0.49%via NVD
CVE-2026-59733High· 8.8
1mo ago

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

▾ Twilightrclone · github.com/rclone/rcloneEPSS 0.55%via GHSA
GHSA-gx4c-2hqx-cw2rLow· 3.1
1mo ago

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-59732Medium· 5.0
1mo ago

rclone archive extract allows S3 destination prefix escape via crafted archive paths

rclone archive extract allows S3 destination prefix escape via crafted archive paths

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.20%via OSV
CVE-2026-71313Medium· 6.9
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent …

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.37%via NVD
CVE-2026-49980Critical· 9.8
3mo ago

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

▾ Midnightrclone · github.com/rclone/rcloneEPSS 0.78%via GHSA
CVE-2026-41176Critical· 9.8PoC
5mo ago

Rclone is a command-line program to sync files and directories to and from different cloud storage providers

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, includin…

▾ Abyssalrclone · rcloneEPSS 3.2%via NVD
CVE-2026-41179Critical· 9.8PoC
5mo ago

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

▾ Abyssalrclone · github.com/rclone/rcloneEPSS 5.3%via OSV
rclone vulnerabilities (CVEs) — page 2 · VulnSea