Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71310

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over an unrestricted buffered reader, allowing a malicious or compromised configured proxy, or an active on-path actor controlling a plaintext HTTP proxy hop, to send oversized headers that grow memory until the rclone process fails. The affected helper is used by FTP and SFTP proxy connections, and SFTP reaches the parser before SSH server authentication, so target host key validation does not constrain a malicious proxy. This issue is fixed in 1.75.0.

A flaw was found in rclone. A remote attacker, by controlling a malicious or compromised proxy server or acting as an on-path attacker for a plaintext HTTP proxy connection, could send oversized HTTP CONNECT response headers. The rclone application's HTTP CONNECT helper processes these responses using an unrestricted buffered reader, leading to unbounded memory growth. This can cause the rclone process to exhaust its memory and terminate, resulting in a Denial of Service (DoS). This vulnerability affects FTP and SFTP proxy connections, with SFTP being vulnerable even before SSH server authentication.

Отчет

This Moderate impact denial of service flaw in rclone arises from unbounded memory growth when processing oversized HTTP CONNECT response headers via FTP or SFTP proxy connections. Exploitation requires a malicious or compromised proxy server, or an active on-path attacker, which limits the attack vector and increases attack complexity.

Меры по смягчению последствий

Avoid routing rclone FTP or SFTP connections through untrusted HTTP proxies. If a proxy is required, ensure it is a trusted, internally controlled endpoint. No mitigation is needed for deployments that do not use HTTP proxies for rclone connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2511772github.com/rclone/rclone: rclone: Denial of Service via unbounded HTTP CONNECT response headers

EPSS

Процентиль: 30%
0.00373
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
11 дней назад

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over an unrestricted buffered reader, allowing a malicious or compromised configured proxy, or an active on-path actor controlling a plaintext HTTP proxy hop, to send oversized headers that grow memory until the rclone process fails. The affected helper is used by FTP and SFTP proxy connections, and SFTP reaches the parser before SSH server authentication, so target host key validation does not constrain a malicious proxy. This issue is fixed in 1.75.0.

CVSS3: 5.9
nvd
11 дней назад

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over an unrestricted buffered reader, allowing a malicious or compromised configured proxy, or an active on-path actor controlling a plaintext HTTP proxy hop, to send oversized headers that grow memory until the rclone process fails. The affected helper is used by FTP and SFTP proxy connections, and SFTP reaches the parser before SSH server authentication, so target host key validation does not constrain a malicious proxy. This issue is fixed in 1.75.0.

CVSS3: 5.9
debian
11 дней назад

rclone is a command-line program to sync files and directories to and ...

CVSS3: 5.9
github
11 дней назад

rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory

EPSS

Процентиль: 30%
0.00373
Низкий

5.9 Medium

CVSS3