Memory Vulnerability in Rclone Affects Cloud Storage Syncing
CVE-2026-71310
5.9MEDIUM
What is CVE-2026-71310?
Rclone is a command-line utility that syncs files and directories across various cloud storage platforms. A flaw in the shared HTTP CONNECT helper component of Rclone allows an attacker to exploit an unrestricted buffered reader when processing proxy CONNECT responses. This vulnerability can lead to memory exhaustion when a malicious proxy sends oversized headers, potentially causing the Rclone process to crash. This issue impacts FTP and SFTP proxy connections, where the vulnerable parser is engaged prior to SSH server authentication, allowing for a breach even without validating the target host's key. The vulnerability has been addressed in version 1.75.0.
Affected Version(s)
rclone < 1.75.0
