rclone 是一个用于在不同云存储提供商之间同步文件和目录的命令行工具。在 1.49.0 至 1.75.1 版本中,HTTP 后端会在 backend/http/http.go 中将通过 --http-headers 或 headers= 配置的请求头附加到请求中,但其使用的 fshttp.NewClient 客户端在跟随重定向时未采用针对特定后端的 http.Client.CheckRedirect 策略。因此,若配置的远程服务器重定向到另一个主机,可能导致如 X-Api-Key 等自定义密钥被重新发送至该不可
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88018 | 9.8 CRITICAL | rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signatu |
| CVE-2026-88044 | 9.1 CRITICAL | rclone: RC per-server auth-proxy bypass |
| CVE-2026-88045 | 7.5 HIGH | rclone: S3 multipart declared-length memory exhaustion |
| CVE-2026-88017 | 7.3 HIGH | rclone: FTP cross-session auth-proxy backend confusion |
| CVE-2026-88016 | 7.1 HIGH | rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclo |
| CVE-2026-88014 | 6.3 MEDIUM | rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive esca |
| CVE-2026-88015 | 5.3 MEDIUM | rclone local: crafted Range request against a translated symlink panics (DoS) |
| CVE-2026-88046 | 5.3 MEDIUM | rclone: source object names can escape the configured root on upload |
No comments yet