Product
Arbitrary File Write Vulnerability in rsync
4 TTPs 1 CVERsync versions prior to 3.5.0 contain an arbitrary file write vulnerability that allows attackers to bypass path confinement by providing absolute paths to specific command-line options.
Multiple Command and Argument Injection Vulnerabilities in rsync
5 TTPs 1 CVEVersions of rsync prior to 3.5.0 contain multiple command and argument injection flaws that allow attackers to execute arbitrary code via malicious hostnames, environment variables, and shell command injections.
Path Traversal Vulnerability in rsync make_path() Function
2 TTPs 1 CVEA path traversal vulnerability in rsync versions prior to 3.5.0 allows a malicious sender to perform arbitrary file writes outside the intended destination directory via crafted relative paths.
CVE-2026-53791 - IP Address Spoofing in rsync Daemon
4 TTPs 1 CVEThe rsync daemon before version 3.5.0 contains a vulnerability where unauthenticated attackers can inject a forged PROXY protocol header to bypass IP-based access control restrictions.
Multiple Vulnerabilities in Rsync
2 rules 4 TTPsMultiple vulnerabilities in Rsync could be exploited by an attacker to elevate privileges, disclose information, bypass security precautions, and perform a denial of service attack.