PT-2026-68329 · Rclone · Rclone

CVE-2026-71310

·

Published

2026-08-05

·

Updated

2026-09-04

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions rclone versions prior to 1.75.0
Description The shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses using http.ReadResponse over an unrestricted buffered reader. This allows a malicious or compromised proxy, or an active on-path actor controlling a plaintext HTTP proxy hop, to send oversized headers. This action causes memory growth until the process fails. The issue affects FTP and SFTP proxy connections; specifically, for SFTP, the parser is reached before SSH server authentication, meaning target host key validation cannot prevent a malicious proxy from triggering the failure.
Recommendations Update to version 1.75.0.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-RCLONE-2026-71310
CVE-2026-71310
GHSA-XHF4-832V-7XCR
GO-2026-6199
OPENSUSE-SU-2026:21761-1

Affected Products

Rclone