Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic | Medium Risk 5.3 | 1 month ago | 2 days ago |
|
|
Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone | Unknown | 1 month ago | 2 days ago |
|
|
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect | Medium Risk 5.3 | 1 month ago | 2 days ago |
|
|
WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone | Unknown | 1 month ago | 2 days ago |
|
|
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote | Low Risk 3.6 | 1 month ago | 2 days ago |
|
|
Unsafe file permission restoration from metadata in github.com/rclone/rclone | Unknown | 1 month ago | 2 days ago |
|
|
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect | Low Risk 3.1 | 1 month ago | 2 days ago |
|
|
S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone | Unknown | 1 month ago | 2 days ago |
|
|
rclone: Path traversal in serve s3 allows reading and overwriting root-level files | Medium Risk 6.5 | 1 month ago | 2 days ago |
|
|
Path traversal in serve s3 in github.com/rclone/rclone | Unknown | 1 month ago | 2 days ago |
|
|
rclone: Verbose Stack Trace Disclosure in RC API Error Responses | Low Risk 2.7 | 1 month ago | 2 days ago |
|
|
Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone | Unknown | 1 month ago | 2 days ago |
|
|
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys | Medium Risk 5.3 | 1 month ago | 2 days ago |
|
|
S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone | Unknown | 1 month ago | 2 days ago |
|
|
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination | Medium Risk 6.5 | 17 days ago | 3 days ago |
|
|
rclone: source object names can escape the configured root on upload | Medium Risk 5.3 | 17 days ago | 9 days ago |
|
|
rclone: source object names can escape the configured root on upload in github.com/rclone/rclone | Unknown | 11 days ago | 9 days ago |
|
|
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace | Medium Risk 6.3 | 17 days ago | 9 days ago |
|
|
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace in github.com/rclone/rclone | Unknown | 11 days ago | 9 days ago |
|
|
rclone: http backend forwards custom/auth headers to a different host on redirect | Low Risk 3.7 | 17 days ago | 9 days ago |
|
|
rclone: http backend forwards custom/auth headers to a different host on redirect in github.com/rclone/rclone | Unknown | 11 days ago | 9 days ago |
|
|
rclone: RC per-server auth-proxy bypass | Critical 9.1 | 17 days ago | 9 days ago |
|
|
rclone: RC per-server auth-proxy bypass in github.com/rclone/rclone | Unknown | 11 days ago | 9 days ago |
|
|
rclone local: crafted Range request against a translated symlink panics (DoS) | Medium Risk 5.3 | 17 days ago | 9 days ago |
|
|
rclone local: crafted Range request against a translated symlink panics (DoS) in github.com/rclone/rclone | Unknown | 11 days ago | 9 days ago |
|
|
rclone: S3 multipart declared-length memory exhaustion | High Risk 7.5 | 17 days ago | 9 days ago |
|
|
rclone: S3 multipart declared-length memory exhaustion in github.com/rclone/rclone | Unknown | 11 days ago | 9 days ago |
|
|
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass | Critical 9.8 | 17 days ago | 10 days ago |
|
|
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass in github.com/rclone/rclone | Unknown | 11 days ago | 10 days ago |
|
|
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination in github.com/rclone/rclone | Unknown | 11 days ago | 10 days ago |
|
|
rclone: FTP cross-session auth-proxy backend confusion | High Risk 7.3 | 17 days ago | 10 days ago |
|
|
rclone: FTP cross-session auth-proxy backend confusion in github.com/rclone/rclone | Unknown | 11 days ago | 10 days ago |
|
|
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory | Medium Risk 5.9 | 1 month ago | 18 days ago |
|
|
rclone: Incomplete path validation allows backend root escape in serve restic | High Risk 8.0 | 1 month ago | 18 days ago |
|
|
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines | Medium Risk 6.4 | 1 month ago | 18 days ago |
|
|
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote | High Risk 7.5 | 1 month ago | 18 days ago |
|
|
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories | High Risk 8.8 | 1 month ago | 18 days ago |
|
|
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution | High Risk 8.0 | 1 month ago | 18 days ago |
|
|
rclone archive extract allows S3 destination prefix escape via crafted archive paths | Medium Risk 5.0 | 1 month ago | 18 days ago |
|
|
rclone: Local Encoding Path Traversal | Medium Risk 6.9 | 1 month ago | 18 days ago |
|
|
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix | Critical 9.8 | 3 months ago | 18 days ago |
|
|
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution | Critical 9.8 | 5 months ago | 18 days ago |
|
|
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution | Critical 9.8 | 5 months ago | 18 days ago |
|
|
Rclone has Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata | Medium Risk 5.5 | 1 year ago | 18 days ago |
|
|
Arbitrary file write via --links symlinks in github.com/rclone/rclone | Unknown | 1 month ago | 1 month ago |
|
|
Command execution via PowerShell smart quotes in github.com/rclone/rclone | Unknown | 1 month ago | 1 month ago |
|
|
Path traversal in serve restic in github.com/rclone/rclone | Unknown | 1 month ago | 1 month ago |
|
|
Path traversal via local backend encoding in github.com/rclone/rclone | Unknown | 1 month ago | 1 month ago |
|
|
Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone | Unknown | 1 month ago | 1 month ago |
|
|
Authorization bypass in serve restic in github.com/rclone/rclone | Unknown | 1 month ago | 1 month ago |
Page 1