Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-79778

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 5.3

Описание

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS uploads to trigger a panic that terminates unrecovered goroutines and halts unrelated work in long-lived processes.

A flaw was found in rclone. In the WebDAV TUS creation handler, a vulnerability allows a malicious or compromised configured endpoint to trigger a denial of service. By resetting connections during TUS uploads, an attacker can cause the application to panic, terminating processes and halting unrelated work. This leads to a complete disruption of service.

Отчет

A flaw was found in rclone. When using the WebDAV backend with TUS (resumable upload) support, a nil pointer dereference panic can occur if the server returns a nil HTTP response during a TUS upload operation. A malicious or misconfigured WebDAV server can trigger this condition, causing the rclone process to crash.

Меры по смягчению последствий

Avoid using rclone's WebDAV backend with TUS-enabled servers from untrusted sources. If TUS uploads are not required, use a WebDAV server configuration that does not advertise TUS support.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2523559github.com/rclone/rclone: rclone: Denial of Service via WebDAV TUS nil-response panic

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
23 дня назад

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS uploads to trigger a panic that terminates unrecovered goroutines and halts unrelated work in long-lived processes.

CVSS3: 5.3
nvd
23 дня назад

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS uploads to trigger a panic that terminates unrecovered goroutines and halts unrelated work in long-lived processes.

CVSS3: 5.3
debian
23 дня назад

rclone before v1.75.0 contains a denial of service vulnerability in th ...

CVSS3: 5.3
github
23 дня назад

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS uploads to trigger a panic that terminates unrecovered goroutines and halts unrelated work in long-lived processes.

5.3 Medium

CVSS3