{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rsync-3.1.0-to-3.4.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-53791"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rsync","rsync (\u003c 3.5.0)","rsync (3.1.0 to 3.4.x)","rsync (3.1.0-3.4.x)"],"_cs_severities":["high"],"_cs_tags":["rsync","vulnerability","cve-2026-53791","spoofing","access-control-bypass","file-read"],"_cs_type":"advisory","_cs_vendors":["rsync"],"content_html":"\u003cp\u003eThe rsync daemon (rsyncd), a popular file synchronization utility, is vulnerable to an IP address spoofing flaw in versions prior to 3.5.0. An unauthenticated remote attacker capable of establishing a direct connection to the rsync service can exploit the daemon's handling of the PROXY protocol. By injecting a crafted PROXY protocol header, an attacker can substitute the true source IP address with a spoofed IP address.\u003c/p\u003e\n\u003cp\u003eThis bypasses configured hosts.allow and hosts.deny access control lists, which rely on the connection source IP for authorization decisions. If an attacker identifies an environment that uses source-IP-based authentication for rsync, they can spoof an address identified as authorized to gain unauthorized access to the filesystem. This vulnerability is particularly critical in environments where rsync is exposed to untrusted networks or where the daemon relies solely on IP-based security primitives for protecting sensitive directory trees.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to bypass network-level access controls, potentially resulting in unauthorized file reads or writes on the rsync server. This poses a significant risk to data integrity and confidentiality in environments that rely on IP-based trust models for file synchronization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of rsync to version 3.5.0 or later to remediate the vulnerability associated with CVE-2026-53791.\u003c/li\u003e\n\u003cli\u003eAudit rsync configurations that utilize the PROXY protocol and consider disabling it if not strictly required.\u003c/li\u003e\n\u003cli\u003eTransition from IP-based access controls to stronger authentication mechanisms, such as SSH-based rsync, which provides cryptographically verified identity, independent of the source connection IP.\u003c/li\u003e\n\u003cli\u003eRestrict network access to rsync daemons at the firewall level to only include explicitly trusted hosts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T15:40:22Z","date_published":"2026-08-13T15:37:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rsync-spoofing/","summary":"The rsync daemon before version 3.5.0 contains a vulnerability where unauthenticated attackers can inject a forged PROXY protocol header to bypass IP-based access control restrictions.","title":"CVE-2026-53791 - IP Address Spoofing in rsync Daemon","url":"https://feed.craftedsignal.io/briefs/2026-08-rsync-spoofing/"}],"language":"en","title":"CraftedSignal Threat Feed - Rsync (3.1.0 to 3.4.x)","version":"https://jsonfeed.org/version/1.1"}