Security: rclone/rclone
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Multiple backends: names from server/third-party listing responses are not confined to the listed directoryGHSA-3vxh-3pcx-9m8q published
Sep 4, 2026 by ncwLow -
local: crafted Range request against a translated symlink panics (DoS), sibling of the already-fixed #6310GHSA-p6m2-r3w9-mpxw published
Sep 4, 2026 by ncwModerate -
serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypassGHSA-xwwr-4h3p-r22c published
Sep 4, 2026 by ncwCritical -
serve docker: a crafted volume name escapes the base mount directory and mounts onto an arbitrary host pathGHSA-p6vx-hf7p-98j6 published
Sep 4, 2026 by ncwLow -
Multiple backends: source object names can escape the configured root on uploadGHSA-38xv-hf3p-h7mq published
Sep 4, 2026 by ncwModerate -
archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespaceGHSA-66hp-wgxq-6f5q published
Sep 4, 2026 by ncwModerate -
http backend forwards custom/auth headers to a different host on redirectGHSA-486v-q2wf-fp2r published
Sep 4, 2026 by ncwLow -
Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destinationGHSA-f8g7-2xjc-7mfh published
Sep 4, 2026 by ncwHigh -
S3 multipart declared-length memory exhaustionGHSA-2p48-j3qc-rx9f published
Sep 4, 2026 by ncwHigh -
FTP cross-session auth-proxy backend confusionGHSA-c476-6w5q-jw77 published
Sep 4, 2026 by ncwHigh