Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

rsync — Vulnerabilities & Security Advisories 42

All 42 CVE vulnerabilities found in rsync, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the rsync file transfer utility, categorized by specific weakness types and security tags. It collects publicly disclosed security flaws affecting various versions of the open-source synchronization tool, covering a historical range from initial releases through the most recent patch cycles. Users can utilize this resource to track vendor security advisories, analyze specific weakness classes like buffer overflows or path traversal issues, and review the complete vulnerability history associated with the product. The compilation focuses on standardizing metadata to facilitate pattern recognition and risk assessment for system administrators and developers managing rsync deployments across different operating systems. By centralizing fragmented security reports, this index provides a structured view of how the software has evolved in response to emerging threats, allowing stakeholders to identify recurring issues and evaluate the frequency of critical patches over time. This approach supports proactive defense strategies by highlighting areas where the codebase has historically been susceptible to exploitation, thereby informing better configuration practices and update schedules for organizations relying on rsync for data integrity and efficient network file management.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-70452 rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure CWE-863 7.4 High 2026-08-13
CVE-2026-70453 rsync < 3.5.0 Algorithmic Complexity DoS via hash_search() CWE-407 7.5 High 2026-08-13
CVE-2026-70454 rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode CWE-295 8.0 High 2026-08-13
CVE-2026-70455 rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion CWE-770 7.5 High 2026-08-13
CVE-2026-70456 rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args() CWE-787 8.2 High 2026-08-13
CVE-2026-70457 rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() CWE-131 6.5 Medium 2026-08-13
CVE-2026-70458 rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling CWE-787 8.2 High 2026-08-13
CVE-2026-70459 rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry CWE-908 5.3 Medium 2026-08-13
CVE-2026-70460 rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink CWE-22 8.1 High 2026-08-13
CVE-2026-70461 rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry CWE-787 8.2 High 2026-08-13
CVE-2026-70462 rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT CWE-190 6.5 Medium 2026-08-13
CVE-2026-70463 rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing CWE-863 8.1 High 2026-08-13
CVE-2026-70464 rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall CWE-770 7.5 High 2026-08-13
CVE-2026-53801 rsync < 3.5.0 Symlink Race Condition Directory Traversal CWE-59 5.9 Medium 2026-08-13
CVE-2026-53800 rsync < 3.5.0 Symlink Race Condition via --remove-source-files CWE-59 4.7 Medium 2026-08-13
CVE-2026-53799 rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application CWE-59 6.3 Medium 2026-08-13
CVE-2026-53797 rsync < 3.5.0 Symlink Race Condition Information Disclosure CWE-59 4.7 Medium 2026-08-13
CVE-2026-53796 rsync < 3.5.0 TOCTOU Race Condition via Destination Directory Handling CWE-59 6.3 Medium 2026-08-13
CVE-2026-53795 rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest CWE-59 8.1 High 2026-08-13
CVE-2026-53794 rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error CWE-1284 5.3 Medium 2026-08-13
CVE-2026-53793 rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode CWE-59 7.4 High 2026-08-13
CVE-2026-53792 rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block CWE-129 6.5 Medium 2026-08-13
CVE-2026-53791 rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header CWE-290 9.1 Critical 2026-08-13
CVE-2026-53790 rsync < 3.5.0 Command Injection via Multiple Code Paths CWE-78 8.1 High 2026-08-13
CVE-2026-53789 rsync < 3.5.0 Arbitrary File Deletion via Malicious File List CWE-807 6.5 Medium 2026-08-13
CVE-2026-53788 rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping CWE-93 6.5 Medium 2026-08-13
CVE-2026-53798 rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping CWE-704 5.3 Medium 2026-08-13
CVE-2026-53786 rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive CWE-863 6.5 Medium 2026-08-13
CVE-2026-53785 rsync < 3.5.0 Path Traversal Write Escape via --relative Mode CWE-59 7.1 High 2026-08-13
CVE-2026-53784 rsync < 3.5.0 Path Traversal via Symlink Module Root CWE-59 7.1 High 2026-08-13

All 42 known CVE vulnerabilities affecting rsync with full Chinese analysis, references, and POCs where available.