Denial of Service Vulnerability in rsync by Rsync Project
CVE-2026-70455

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-70455?

An issue in rsync versions prior to 3.5.0 allows remote attackers to exploit a denial of service vulnerability. Specifically, the short alias --zt for --compress-threads bypasses certain configuration options, allowing malicious users to specify an excessively high value for Zstandard worker threads. This results in the unbounded creation of threads on the receiving server, ultimately leading to resource exhaustion. Administrators are advised to upgrade to rsync version 3.5.0 or later to mitigate this vulnerability.

Affected Version(s)

rsync 3.4.2 <= 3.4.4

rsync 3.5.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

fcasal
.