PT-2026-68329 · Rclone · Rclone
CVE-2026-71310
·
Published
2026-08-05
·
Updated
2026-09-04
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
rclone versions prior to 1.75.0
Description
The shared HTTP CONNECT helper in
lib/proxy/http.go parses proxy CONNECT responses using http.ReadResponse over an unrestricted buffered reader. This allows a malicious or compromised proxy, or an active on-path actor controlling a plaintext HTTP proxy hop, to send oversized headers. This action causes memory growth until the process fails. The issue affects FTP and SFTP proxy connections; specifically, for SFTP, the parser is reached before SSH server authentication, meaning target host key validation cannot prevent a malicious proxy from triggering the failure.Recommendations
Update to version 1.75.0.
Exploit
Fix
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rclone