Threats Tagged 'cve-2026-53793'
View all threats tagged with 'cve-2026-53793'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-53793'
Click on any threat for detailed analysis and mitigation recommendations
The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool. Security Fix(es): * rsync: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460) * rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions (CVE-2026-70454) * rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789) * rsync: rsync < 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790) * rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458) * rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464) * rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803) * rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784) * rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463) * rsync: rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452) * rsync: rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header (CVE-2026-53791) * rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795) * rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456) * rsync: rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793) * rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453) * rsync: rsync: Memory corruption via out-of-bounds write in size parsing (CVE-2026-70457) * rsync: rsync: Information disclosure and denial of service via crafted files-from entry (CVE-2026-70461) * rsync: rsync: Arbitrary File Read via Symlink Following (CVE-2026-53802) * rsync: rsync: Arbitrary file write via path traversal in --relative mode (CVE-2026-53785) * rsync: rsync: Directory escape via TOCTOU race condition in rrsync (CVE-2026-53783) Bug Fix(es) and Enhancement(s): * Rebase rsync to version 3.2.7 in RHEL9 (JIRA:RHEL-248835) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/14/2026, 19:43:00 UTC Added: 09/15/2026, 01:37:48 UTC |
The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool. Security Fix(es): * rsync: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460) * rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions (CVE-2026-70454) * rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789) * rsync: rsync < 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790) * rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458) * rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464) * rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803) * rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784) * rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463) * rsync: rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452) * rsync: rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header (CVE-2026-53791) * rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795) * rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456) * rsync: rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793) * rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453) * rsync: rsync: Denial of Service via Zstandard compression thread exhaustion (CVE-2026-70455) * rsync: rsync: Memory corruption via out-of-bounds write in size parsing (CVE-2026-70457) * rsync: rsync: Information disclosure and denial of service via crafted files-from entry (CVE-2026-70461) * rsync: rsync: Arbitrary File Read via Symlink Following (CVE-2026-53802) * rsync: rsync: Arbitrary file write via path traversal in --relative mode (CVE-2026-53785) * rsync: rsync: Directory escape via TOCTOU race condition in rrsync (CVE-2026-53783) Bug Fix(es) and Enhancement(s): * Rebase rsync to version 3.5.0 in RHEL10 (JIRA:RHEL-246094) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/14/2026, 19:33:06 UTC Added: 09/15/2026, 01:37:48 UTC |
0 A security update for rsync addresses multiple vulnerabilities including directory escape issues, command injection, symlink races, denial of service, privilege escalation, and unauthorized file access. These vulnerabilities affect various rsync daemon and sender/receiver functionalities, potentially allowing attackers to bypass restrictions, execute arbitrary commands, cause crashes, or manipulate files outside intended directories. The update fixes a broad set of issues identified by CVE identifiers ranging from CVE-2026-53783 to CVE-2026-70464. Join the discussion | GCVE Database | 08/26/2026, 12:30:55 UTC Added: 09/17/2026, 01:58:55 UTC |
0 CVE-2026-53793 is a critical vulnerability in rsync versions up to 3.4.4 that allows remote clients to bypass path confinement. By exploiting improper handling of the /./ boundary marker in module roots, attackers can access files outside the intended directory subtree, potentially gaining unauthorized read or write access. Join the discussion | CVE Database V5 | 08/13/2026, 14:38:42 UTC Added: 08/13/2026, 15:12:04 UTC |
GCVE Database | 08/12/2026, 22:00:00 UTC Added: 05/26/2026, 20:58:48 UTC |
Showing 1 to 5 of 5 results