Denial of Service Vulnerability in Rsync Daemon by Rsync Project
CVE-2026-70464

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-70464?

The Rsync Daemon contains a denial of service vulnerability that permits unauthenticated remote attackers to exhaust the available connection slots. By manipulating the handshake process before or after module selection, attackers can exploit this vulnerability to stall connections without triggering I/O timeouts, ultimately denying service to legitimate users. This could be accomplished by establishing numerous simultaneous connections and controlling the data transfer rate to prevent timeout events. As a result, the Rsync Daemon could become unavailable, affecting normal operations.

Affected Version(s)

rsync 2.0.0 <= 3.4.4

rsync 3.5.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mruprich
.