RsyncProject Rsync是RsyncProject组织开源的一款速度快、功能极其强大的文件复制工具,可用于复制远程文件和本地文件。 RsyncProject Rsync 3.1.0版本至3.5.0之前版本存在授权问题漏洞,该漏洞源于auth users指令解析时仅使用逗号分隔用户列表,无法正确处理包含空格的@Group Name条目,导致拒绝规则被静默丢弃,已认证用户可连接到受限模块,造成授权绕过。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| RsyncProject | rsync | 3.1.0≤ 3.4.4 |
affected |
3.5.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RsyncProject | rsync | 3.1.0 ~ 3.4.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-53791 | 9.1 CRITICAL | rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header |
| CVE-2026-70461 | 8.2 HIGH | rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry |
| CVE-2026-70456 | 8.2 HIGH | rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args() |
| CVE-2026-70458 | 8.2 HIGH | rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling |
| CVE-2026-53790 | 8.1 HIGH | rsync < 3.5.0 Command Injection via Multiple Code Paths |
| CVE-2026-53795 | 8.1 HIGH | rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest |
| CVE-2026-70460 | 8.1 HIGH | rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink |
| CVE-2026-53783 | 8.1 HIGH | rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync |
| CVE-2026-70454 | 8.0 HIGH | rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode |
| CVE-2026-53803 | 7.8 HIGH | rsync < 3.5.0 Symlink Following Arbitrary File Overwrite |
| CVE-2026-70455 | 7.5 HIGH | rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion |
| CVE-2026-70464 | 7.5 HIGH | rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall |
| CVE-2026-70453 | 7.5 HIGH | rsync < 3.5.0 Algorithmic Complexity DoS via hash_search() |
| CVE-2026-53793 | 7.4 HIGH | rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode |
| CVE-2026-70452 | 7.4 HIGH | rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure |
| CVE-2026-53802 | 7.1 HIGH | rsync < 3.5.0 Arbitrary File Read via Symlink Following |
| CVE-2026-53785 | 7.1 HIGH | rsync < 3.5.0 Path Traversal Write Escape via --relative Mode |
| CVE-2026-53784 | 7.1 HIGH | rsync < 3.5.0 Path Traversal via Symlink Module Root |
| CVE-2026-70462 | 6.5 MEDIUM | rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT |
| CVE-2026-70457 | 6.5 MEDIUM | rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() |
Showing top 20 of 33 CVEs. View all on vendor page → →
No comments yet