Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-79776

Опубликовано: 25 авг. 2026
Источник: debian

Описание

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rcloneunfixedpackage

Примечания

  • https://github.com/rclone/rclone/security/advisories/GHSA-mfvx-7rcj-9m5g

Связанные уязвимости

CVSS3: 5.3
ubuntu
22 дня назад

(rclone before 1.75.0 mounts the pprof debug handler as its own router ...)

CVSS3: 5.3
nvd
23 дня назад

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials.

CVSS3: 5.3
github
23 дня назад

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials.