Vulnerabilidades em rclone
32 resultadosAnálise Vexday
O rclone possui 7 CVEs catalogadas, com 4 publicadas nos últimos 90 dias, indicando atividade recente de descoberta de vulnerabilidades. Nenhuma das falhas está sob exploração ativa conhecida, mas 3 são classificadas como críticas, predominantemente relacionadas a autenticação insuficiente (CWE-306). O risco permanece moderado, exigindo atenção às atualizações recentes para mitigar as falhas críticas identificadas.
CVE-2026-41179CRITICALRClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command executionEPSS 5.3%CVE-2026-41176CRITICALRclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command executionEPSS 3.2%CVE-2026-49980CRITICALRclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fixEPSS 0.8%CVE-2026-88018CRITICALrclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypassEPSS 0.8%CVE-2026-88045HIGHrclone: S3 multipart declared-length memory exhaustionEPSS 0.6%CVE-2026-71310MEDIUMrclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone MemoryEPSS 0.6%CVE-2026-88044CRITICALrclone: RC per-server auth-proxy bypassEPSS 0.6%CVE-2026-59733HIGHrclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositoriesEPSS 0.6%CVE-2026-88015MEDIUMrclone local: crafted Range request against a translated symlink panics (DoS)EPSS 0.5%CVE-2026-71312HIGHrclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command ExecutionEPSS 0.5%CVE-2026-71309HIGHrclone: Incomplete path validation allows backend root escape in serve resticEPSS 0.5%CVE-2026-79775HIGHrclone Archive Backend SquashFS Parser Denial of ServiceEPSS 0.4%CVE-2026-79776MEDIUMrclone before 1.75.0 Authentication Bypass via pprofEPSS 0.4%CVE-2026-88017HIGHrclone: FTP cross-session auth-proxy backend confusionEPSS 0.4%CVE-2026-54572HIGHrclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remoteEPSS 0.4%CVE-2026-71311MEDIUMrclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves NewlinesEPSS 0.4%CVE-2026-88046MEDIUMrclone: source object names can escape the configured root on uploadEPSS 0.4%CVE-2026-71313MEDIUMrclone: Local Encoding Path TraversalEPSS 0.4%CVE-2026-79781MEDIUMrclone serve s3 Path Traversal via dot-dot object keysEPSS 0.3%CVE-2026-79777MEDIUMrclone before v1.75.0 Information Disclosure via RC APIEPSS 0.3%