Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

RsyncProject — Vulnerabilities & Security Advisories 39

Browse all 39 CVE security advisories affecting RsyncProject. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the vendor RsyncProject, focusing on the open-source file transfer and synchronization utility. The collection compiles reported security flaws and their remediations within the Rsync software suite, covering a historical range that spans multiple years of active development and security maintenance. By reviewing these entries, users can track the vendor's advisory history, analyze the specific types of weaknesses such as memory corruption or improper input validation, and evaluate the overall security posture of the product over time. This aggregation serves as a technical reference for security professionals, developers, and system administrators seeking to understand the risk landscape of Rsync implementations in their infrastructure. The data allows for the identification of recurring vulnerability patterns and the assessment of patching effectiveness across different release cycles. Readers are encouraged to use this index to correlate internal security findings with public disclosure records, ensuring that deployed versions of Rsync are adequately protected against known exploitation vectors. The page prioritizes clarity and factual accuracy, presenting each vulnerability with its corresponding impact, affected versions, and recommended mitigation strategies without editorial commentary or promotional content. This structured overview facilitates efficient threat intelligence gathering and supports the development of robust security policies for environments relying on Rsync for automated data replication and backup operations.

Top products by RsyncProject: rsync
CVE ID Title CVSS Severity Published
CVE-2026-70452 rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure — rsync CWE-863 7.4 High 2026-08-13
CVE-2026-70453 rsync < 3.5.0 Algorithmic Complexity DoS via hash_search() — rsync CWE-407 7.5 High 2026-08-13
CVE-2026-70454 rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode — rsync CWE-295 8.0 High 2026-08-13
CVE-2026-70455 rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion — rsync CWE-770 7.5 High 2026-08-13
CVE-2026-70456 rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args() — rsync CWE-787 8.2 High 2026-08-13
CVE-2026-70457 rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() — rsync CWE-131 6.5 Medium 2026-08-13
CVE-2026-70458 rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling — rsync CWE-787 8.2 High 2026-08-13
CVE-2026-70459 rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry — rsync CWE-908 5.3 Medium 2026-08-13
CVE-2026-70460 rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink — rsync CWE-22 8.1 High 2026-08-13
CVE-2026-70461 rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry — rsync CWE-787 8.2 High 2026-08-13
CVE-2026-70462 rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT — rsync CWE-190 6.5 Medium 2026-08-13
CVE-2026-70463 rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing — rsync CWE-863 8.1 High 2026-08-13
CVE-2026-70464 rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall — rsync CWE-770 7.5 High 2026-08-13
CVE-2026-53801 rsync < 3.5.0 Symlink Race Condition Directory Traversal — rsync CWE-59 5.9 Medium 2026-08-13
CVE-2026-53800 rsync < 3.5.0 Symlink Race Condition via --remove-source-files — rsync CWE-59 4.7 Medium 2026-08-13
CVE-2026-53799 rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application — rsync CWE-59 6.3 Medium 2026-08-13
CVE-2026-53797 rsync < 3.5.0 Symlink Race Condition Information Disclosure — rsync CWE-59 4.7 Medium 2026-08-13
CVE-2026-53796 rsync < 3.5.0 TOCTOU Race Condition via Destination Directory Handling — rsync CWE-59 6.3 Medium 2026-08-13
CVE-2026-53795 rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest — rsync CWE-59 8.1 High 2026-08-13
CVE-2026-53794 rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error — rsync CWE-1284 5.3 Medium 2026-08-13
CVE-2026-53793 rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode — rsync CWE-59 7.4 High 2026-08-13
CVE-2026-53792 rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block — rsync CWE-129 6.5 Medium 2026-08-13
CVE-2026-53791 rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header — rsync CWE-290 9.1 Critical 2026-08-13
CVE-2026-53790 rsync < 3.5.0 Command Injection via Multiple Code Paths — rsync CWE-78 8.1 High 2026-08-13
CVE-2026-53789 rsync < 3.5.0 Arbitrary File Deletion via Malicious File List — rsync CWE-807 6.5 Medium 2026-08-13
CVE-2026-53788 rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping — rsync CWE-93 6.5 Medium 2026-08-13
CVE-2026-53798 rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping — rsync CWE-704 5.3 Medium 2026-08-13
CVE-2026-53786 rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive — rsync CWE-863 6.5 Medium 2026-08-13
CVE-2026-53785 rsync < 3.5.0 Path Traversal Write Escape via --relative Mode — rsync CWE-59 7.1 High 2026-08-13
CVE-2026-53784 rsync < 3.5.0 Path Traversal via Symlink Module Root — rsync CWE-59 7.1 High 2026-08-13

This page lists every published CVE security advisory associated with RsyncProject. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.