Rsyncproject Rsync vulnerabilities
43 known vulnerabilities affecting rsyncproject/rsync.
Total CVEs
43
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH23MEDIUM18LOW1
Vulnerabilities
Page 3 of 3
CVE-2026-53797P4MEDIUMCVSS 4.7≤ 3.4.42026-08-13
CVE-2026-53797 [MEDIUM] CWE-59 CVE-2026-53797: rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree trave
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an attacker who can manipulate a parent directory of the source tree to redirect file reads to unintended paths. Attackers can atomically replace a parent directory component with a symlink pointing outside the source root between path
nvd
CVE-2026-53800P4MEDIUMCVSS 4.7≤ 3.4.42026-08-13
CVE-2026-53800 [MEDIUM] CWE-59 CVE-2026-53800: rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feat
rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows attackers with symlink creation access to cause arbitrary file deletion. Attackers can atomically substitute a symlink for a source file between transfer completion and the unlink() call, causing rsync to delete the symlink target rathe
nvd
CVE-2026-45232P4LOWCVSS 3.7fixed in 3.4.32026-05-20
CVE-2026-45232 [LOW] CWE-193 CVE-2026-45232: Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the est
Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy se
nvd
← Previous3 / 3