Vulnerabilidades em rclone
32 resultadosAnálise Vexday
O rclone possui 7 CVEs catalogadas, com 4 publicadas nos últimos 90 dias, indicando atividade recente de descoberta de vulnerabilidades. Nenhuma das falhas está sob exploração ativa conhecida, mas 3 são classificadas como críticas, predominantemente relacionadas a autenticação insuficiente (CWE-306). O risco permanece moderado, exigindo atenção às atualizações recentes para mitigar as falhas críticas identificadas.
CVE-2026-79778MEDIUMrclone before v1.75.0 Denial of Service via TUS nil-response panicEPSS 0.3%CVE-2026-93986LOWrclone before 1.75.1 Path Traversal via Directory Listing NamesEPSS 0.3%CVE-2026-88016HIGHrclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destinationEPSS 0.3%CVE-2024-52522MEDIUMRclone Improper Permission and Ownership Handling on Symlink Targets with --links and --metadataEPSS 0.2%CVE-2026-79782CRITICALrclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP RedirectEPSS 0.2%CVE-2026-59732MEDIUMrclone archive extract allows S3 destination prefix escape via crafted archive pathsEPSS 0.2%CVE-2026-88014MEDIUMrclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespaceEPSS 0.2%CVE-2026-88013LOWrclone: http backend forwards custom/auth headers to a different host on redirectEPSS 0.2%CVE-2026-79783LOWrclone before 1.74.4 Privilege Escalation via setuid MetadataEPSS 0.2%CVE-2026-93987MEDIUMrclone serve docker Path Traversal via Volume NameEPSS 0.2%CVE-2026-79779MEDIUMrclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP RedirectEPSS 0.1%CVE-2026-79780MEDIUMrclone before v1.75.0 Credential Exposure via S3 RedirectEPSS 0.1%