TLS Certificate Validation Vulnerability in rsync by Rsync Project
CVE-2026-70454
7.6HIGH
What is CVE-2026-70454?
The vulnerability in rsync versions 3.2.0 to 3.2.3 and rsync-ssl versions up to 3.4.4 allows attackers to exploit inadequate validation of TLS certificates. This can enable on-path attackers to present unauthorized certificates, thereby intercepting encrypted sessions. Due to the failure in validating server certificates against trusted Certificate Authorities and hostname matching, attackers can manipulate rsync session content without detection by users, leading to potential data breaches. For more details on this issue, you can refer to the official GitHub Security Advisory and related resources.
Affected Version(s)
rsync 0 <= 3.4.4
rsync 3.5.0
