Skip to content
Threat Feed

Product

Rsync

5 briefs RSS
high advisory

Arbitrary File Write Vulnerability in rsync

Rsync versions prior to 3.5.0 contain an arbitrary file write vulnerability that allows attackers to bypass path confinement by providing absolute paths to specific command-line options.

rsync
4t 1c
high advisory

Multiple Command and Argument Injection Vulnerabilities in rsync

Versions of rsync prior to 3.5.0 contain multiple command and argument injection flaws that allow attackers to execute arbitrary code via malicious hostnames, environment variables, and shell command injections.

rsync +1 vulnerability command-injection file-transfer cve-2026-53793 denial-of-service network
5t 1c
high advisory

Path Traversal Vulnerability in rsync make_path() Function

A path traversal vulnerability in rsync versions prior to 3.5.0 allows a malicious sender to perform arbitrary file writes outside the intended destination directory via crafted relative paths.

rsync
2t 1c
high advisory

CVE-2026-53791 - IP Address Spoofing in rsync Daemon

The rsync daemon before version 3.5.0 contains a vulnerability where unauthenticated attackers can inject a forged PROXY protocol header to bypass IP-based access control restrictions.

rsync +3 vulnerability cve-2026-53791 spoofing access-control-bypass file-read
4t 1c
high advisory

Multiple Vulnerabilities in Rsync

Multiple vulnerabilities in Rsync could be exploited by an attacker to elevate privileges, disclose information, bypass security precautions, and perform a denial of service attack.

rsync vulnerability privilege-escalation information-gathering defense-evasion impact
2r 4t