Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2026-53789

около 1 месяца назад

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-53789

около 1 месяца назад

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-53789

около 1 месяца назад

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-53789

28 дней назад

rsync < 3.5.0 Arbitrary File Deletion via Malicious File List

EPSS: Низкий
debian логотип

CVE-2026-53789

около 1 месяца назад

rsync before 3.5.0contains an improper path handling vulnerability tha ...

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2026:67462

5 дней назад

Important: rsync security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-67462-0

5 дней назад

ELSA-2026-67462-0: rsync security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:67463

5 дней назад

Important: rsync security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-67463-0

5 дней назад

ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3657-1

около 1 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3634-1

около 1 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21650-1

25 дней назад

Security update for rsync

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-53789

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-53789

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-53789

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-53789

rsync < 3.5.0 Arbitrary File Deletion via Malicious File List

0%
Низкий
28 дней назад
debian логотип
CVE-2026-53789

rsync before 3.5.0contains an improper path handling vulnerability tha ...

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:67462

Important: rsync security, bug fix, and enhancement update

5 дней назад
oracle-oval логотип
ELSA-2026-67462-0

ELSA-2026-67462-0: rsync security, bug fix, and enhancement update (IMPORTANT)

5 дней назад
rocky логотип
RLSA-2026:67463

Important: rsync security, bug fix, and enhancement update

5 дней назад
oracle-oval логотип
ELSA-2026-67463-0

ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT)

5 дней назад
suse-cvrf логотип
SUSE-SU-2026:3657-1

Security update for rsync

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3634-1

Security update for rsync

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21650-1

Security update for rsync

25 дней назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.