Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/rsync

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Rsync is an open source utility that provides fast incremental file transfer. It uses the "rsync algorithm" which provides a very fast method for bringing remote files into sync. It does this by sending just the differences in the files across the link, without requiring that both sets of files are present at one of the ends of the link beforehand. Security Fix(es): Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.(CVE-2026-43619) rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree.(CVE-2026-53783) rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access.(CVE-2026-53784) rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path() function follows symlinks pointing outside the destination tree while creating intermediate directories without verifying that created paths remain within the destination boundary, enabling arbitrary file writes on the receiver's filesystem.(CVE-2026-53785) rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directives during filter evaluation to introduce rules that supersede daemon module-level restrictions, gaining access to files the module filter was intended to exclude.(CVE-2026-53786) rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters. Attackers can inject malicious newline characters into names communicated over the pipe-based line-oriented protocol to cause the rsync daemon to process attacker-influenced data as legitimate protocol input, corrupting uid/gid mapping logic.(CVE-2026-53788) rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory.(CVE-2026-53789) rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.(CVE-2026-53790) rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the

Join the discussion

Rsync versions 3.1.0 through 3.4.4 contain an access control bypass vulnerability that allows remote attackers to circumvent hostname-based deny rules. This occurs because the rsync daemon skips deny rules when DNS lookups for hostnames fail, enabling unauthorized access to restricted module file trees. The vulnerability is critical with a CVSS score of 9.1.

Join the discussion

CVE-2026-70453 is a high-severity vulnerability in rsync versions up to 3.4.4. It involves an algorithmic complexity issue in the hash_search() function that allows a remote attacker to cause a denial of service by sending a specially crafted file list. This triggers quadratic-time hash lookups, exhausting CPU resources on the receiver side and causing sustained service disruption.

Join the discussion

Rsync versions 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) have a TLS certificate validation vulnerability. This flaw allows on-path attackers to intercept encrypted sessions by using self-signed or invalid certificates. The vulnerability arises from failure to properly validate server TLS certificates against trusted CAs and verify hostname matching. Exploitation can lead to decryption or tampering of rsync session content without client detection.

Join the discussion

Rsync versions 3.4.2 through 3.4.4 contain a denial of service vulnerability where a remote sender can exhaust system resources by abusing the --zt alias for --compress-threads. This bypasses option filtering and allows spawning an unbounded number of worker threads, leading to resource exhaustion.

Join the discussion

An out-of-bounds write vulnerability exists in rsync versions 3.0.1 through 3.4.4 in the read_args() function. This flaw allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list that causes the argv allocation to be exactly full, resulting in the trailing NULL terminator being written beyond the allocated boundary.

Join the discussion

A high-severity vulnerability (CVE-2026-70457) exists in rsync versions 3.2.3 through 3.4.4. It involves an out-of-bounds write in the parse_size_arg() function due to improper handling of snprintf() return values, leading to memory corruption in the .bss segment. This flaw arises because the return value of snprintf() is used as an index without bounds checking when the formatted string is truncated.

Join the discussion

An out-of-bounds write vulnerability exists in rsync versions 3.0.0 through 3.4.4. This flaw occurs during processing of file entries with the FLAG_HLINKED flag when hard-link preservation is inactive, leading to memory corruption. The vulnerability arises from missing F_SUM field in the file_struct layout, allowing access beyond allocated memory. The issue has a high severity score of 8.8 and affects multiple Ubuntu LTS versions. No official patch or remediation guidance has been confirmed yet.

Join the discussion

A null pointer dereference vulnerability exists in rsync versions 3.0.0 through 3.4.4 in the daemon child process. This occurs when the daemon receives a file list whose first entry is a dot entry not typed as a directory, causing the daemon to dereference an invalid pointer and crash the client connection. The vulnerability has a medium severity with a CVSS score of 6.9.

Join the discussion

A path traversal vulnerability exists in rsync versions 2.3.3 through 3.4.4 that allows a malicious sender to escape the module root directory by exploiting symbolic links when using the --partial-dir or --backup-dir options. This can lead to arbitrary file writes outside the intended directory. The vulnerability requires the attacker to have write access to place or exploit symlinks under the module root.

Join the discussion

Showing 1 to 10 of 40 results

Filters:Package: pkg:github/rsync
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses