IP Address Spoofing Vulnerability in Rsync Daemon by Rsync Project
CVE-2026-53791

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-53791?

The Rsync daemon prior to version 3.5.0 is susceptible to an IP address spoofing flaw that enables unauthenticated remote attackers to sidestep IP-based access restrictions. By manipulating the PROXY protocol header to include a counterfeit source IP address, attackers can connect directly to the rsync daemon and bypass existing host allow/deny rules. This vulnerability poses significant risks, as it permits unauthorized access to the system, which is typically reserved for legitimate users based on their actual source addresses.

Affected Version(s)

rsync 0 <= 3.4.4

rsync 3.5.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.