NIXPKGS-2026-2562
GitHub issue
published 8 hours ago
rclone: security issues < 1.75.1
Permalink
CVE-2026-88045
7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
9 packages
- librclone
- rclone-ui
- syncrclone
- rclone-browser
- plakar-plugin-rclone
- git-annex-remote-rclone
- gnomeExtensions.rclone-manager
- python313Packages.rclone-python
- python314Packages.rclone-python
- @LeSuisse ignored maintainer @SuperSandro2000 maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
rclone: S3 multipart declared-length memory exhaustion
-
-
https://github.com/rclone/rclone/issues/9616 x_refsource_MISC
-
https://github.com/rclone/rclone/releases/tag/v1.75.1 x_refsource_MISC
rclone
- ==>= 1.75.0, < 1.75.1
Permalink
CVE-2026-88044
9.1 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
9 packages
- librclone
- rclone-ui
- syncrclone
- rclone-browser
- plakar-plugin-rclone
- git-annex-remote-rclone
- gnomeExtensions.rclone-manager
- python313Packages.rclone-python
- python314Packages.rclone-python
- @LeSuisse ignored maintainer @SuperSandro2000 maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
rclone: RC per-server auth-proxy bypass
-
-
https://github.com/rclone/rclone/releases/tag/v1.75.1 x_refsource_MISC
rclone
- ==>= 1.70.0, < 1.75.1
Permalink
CVE-2026-88018
9.8 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
9 packages
- librclone
- rclone-ui
- syncrclone
- rclone-browser
- plakar-plugin-rclone
- git-annex-remote-rclone
- gnomeExtensions.rclone-manager
- python313Packages.rclone-python
- python314Packages.rclone-python
- @LeSuisse ignored maintainer @SuperSandro2000 maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
-
-
https://github.com/rclone/rclone/releases/tag/v1.75.1 x_refsource_MISC
rclone
- ==< 1.75.1
Permalink
CVE-2026-88017
7.3 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
9 packages
- librclone
- rclone-ui
- syncrclone
- rclone-browser
- plakar-plugin-rclone
- git-annex-remote-rclone
- gnomeExtensions.rclone-manager
- python313Packages.rclone-python
- python314Packages.rclone-python
- @LeSuisse ignored maintainer @SuperSandro2000 maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
rclone: FTP cross-session auth-proxy backend confusion
-
https://github.com/rclone/rclone/security/advisories/GHSA-c476-6w5q-jw77 x_refsource_CONFIRM
-
https://github.com/rclone/rclone/releases/tag/v1.75.1 x_refsource_MISC
rclone
- ==>= 1.64.0, < 1.75.1
Permalink
CVE-2026-88015
5.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): Low (L)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
9 packages
- librclone
- rclone-ui
- syncrclone
- rclone-browser
- plakar-plugin-rclone
- git-annex-remote-rclone
- gnomeExtensions.rclone-manager
- python313Packages.rclone-python
- python314Packages.rclone-python
- @LeSuisse accepted
- @LeSuisse ignored maintainer @SuperSandro2000 maintainer.ignore
- @LeSuisse published on GitHub
rclone local: crafted Range request against a translated symlink panics (DoS)
-
-
https://github.com/rclone/rclone/releases/tag/v1.75.1 x_refsource_MISC
rclone
- ==< 1.75.1
Permalink
CVE-2026-88013
3.7 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
9 packages
- librclone
- rclone-ui
- syncrclone
- rclone-browser
- plakar-plugin-rclone
- git-annex-remote-rclone
- gnomeExtensions.rclone-manager
- python313Packages.rclone-python
- python314Packages.rclone-python
- @LeSuisse ignored maintainer @SuperSandro2000 maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
rclone: http backend forwards custom/auth headers to a different host on redirect
-
-
https://github.com/rclone/rclone/releases/tag/v1.75.1 x_refsource_MISC
rclone
- ==>= 1.49.0, < 1.75.1
Permalink
CVE-2026-88046
5.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
9 packages
- librclone
- rclone-ui
- syncrclone
- rclone-browser
- plakar-plugin-rclone
- git-annex-remote-rclone
- gnomeExtensions.rclone-manager
- python313Packages.rclone-python
- python314Packages.rclone-python
- @LeSuisse ignored maintainer @SuperSandro2000 maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
rclone: source object names can escape the configured root on upload
-
https://github.com/rclone/rclone/security/advisories/GHSA-38xv-hf3p-h7mq x_refsource_CONFIRM
-
https://github.com/rclone/rclone/releases/tag/v1.75.1 x_refsource_MISC
rclone
- ==< 1.75.1
Permalink
CVE-2026-88016
7.1 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): Low (L)
- Integrity (I): High (H)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): Low (L)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
9 packages
- librclone
- rclone-ui
- syncrclone
- rclone-browser
- plakar-plugin-rclone
- git-annex-remote-rclone
- gnomeExtensions.rclone-manager
- python313Packages.rclone-python
- python314Packages.rclone-python
- @LeSuisse ignored maintainer @SuperSandro2000 maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
-
https://github.com/rclone/rclone/security/advisories/GHSA-f8g7-2xjc-7mfh x_refsource_CONFIRM
-
https://github.com/rclone/rclone/releases/tag/v1.75.1 x_refsource_MISC
rclone
- ==< 1.75.1
Permalink
CVE-2026-88014
6.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): None (N)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
9 packages
- librclone
- rclone-ui
- syncrclone
- rclone-browser
- plakar-plugin-rclone
- git-annex-remote-rclone
- gnomeExtensions.rclone-manager
- python313Packages.rclone-python
- python314Packages.rclone-python
- @LeSuisse accepted
- @LeSuisse ignored maintainer @SuperSandro2000 maintainer.ignore
- @LeSuisse published on GitHub
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
-
-
https://github.com/rclone/rclone/releases/tag/v1.75.1 x_refsource_MISC
rclone
- ==>= 1.72.0, < 1.75.1