RsyncProject Rsync是RsyncProject组织开源的一款速度快、功能极其强大的文件复制工具,可用于复制远程文件和本地文件。 RsyncProject Rsync 3.5.0之前版本存在安全漏洞,该漏洞源于--remove-source-files功能存在符号链接竞争条件,攻击者可在传输完成和unlink()调用之间用符号链接替换源文件,导致删除任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| RsyncProject | rsync | ≤ 3.4.4 |
affected |
3.5.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RsyncProject | rsync | 0 ~ 3.4.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53791 | 9.1 CRITICAL | rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header |
| CVE-2026-70461 | 8.2 HIGH | rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry |
| CVE-2026-70456 | 8.2 HIGH | rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args() |
| CVE-2026-70458 | 8.2 HIGH | rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling |
| CVE-2026-70463 | 8.1 HIGH | rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing |
| CVE-2026-53790 | 8.1 HIGH | rsync < 3.5.0 Command Injection via Multiple Code Paths |
| CVE-2026-53795 | 8.1 HIGH | rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest |
| CVE-2026-70460 | 8.1 HIGH | rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink |
| CVE-2026-53783 | 8.1 HIGH | rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync |
| CVE-2026-70454 | 8.0 HIGH | rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode |
| CVE-2026-53803 | 7.8 HIGH | rsync < 3.5.0 Symlink Following Arbitrary File Overwrite |
| CVE-2026-70455 | 7.5 HIGH | rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion |
| CVE-2026-70464 | 7.5 HIGH | rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall |
| CVE-2026-70453 | 7.5 HIGH | rsync < 3.5.0 Algorithmic Complexity DoS via hash_search() |
| CVE-2026-70452 | 7.4 HIGH | rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure |
| CVE-2026-53793 | 7.4 HIGH | rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode |
| CVE-2026-53802 | 7.1 HIGH | rsync < 3.5.0 Arbitrary File Read via Symlink Following |
| CVE-2026-53784 | 7.1 HIGH | rsync < 3.5.0 Path Traversal via Symlink Module Root |
| CVE-2026-53785 | 7.1 HIGH | rsync < 3.5.0 Path Traversal Write Escape via --relative Mode |
| CVE-2026-70462 | 6.5 MEDIUM | rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT |
Showing top 20 of 33 CVEs. View all on vendor page → →
No comments yet