Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-79777

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 2.7

Описание

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

A flaw was found in rclone. Attackers can exploit this vulnerability by triggering panics in the RC API error responses. This can lead to the disclosure of sensitive internal information, such as file paths, module versions, goroutine states, and memory addresses, potentially aiding further attacks.

Отчет

A flaw was found in rclone. The Remote Control (RC) API can include sensitive information such as internal paths, configuration details, or error context in error responses. An authenticated administrator with access to the RC API can observe this information, which may aid in further attacks against the system.

Меры по смягчению последствий

Restrict access to the rclone RC API to trusted networks and administrators only. Use the --rc-allow-origin and --rc-user/--rc-pass flags to enforce authentication. Where possible, disable the RC API entirely if not required for operations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=2523555github.com/rclone/rclone: rclone: Information Disclosure via RC API error responses

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
ubuntu
23 дня назад

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

CVSS3: 2.7
nvd
23 дня назад

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

CVSS3: 2.7
debian
23 дня назад

rclone before v1.75.0 includes full Go stack traces in RC API error re ...

CVSS3: 2.7
github
23 дня назад

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

2.7 Low

CVSS3