Memory Vulnerability in Rclone Affects Cloud Storage Syncing
CVE-2026-71310

5.9MEDIUM

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71310?

Rclone is a command-line utility that syncs files and directories across various cloud storage platforms. A flaw in the shared HTTP CONNECT helper component of Rclone allows an attacker to exploit an unrestricted buffered reader when processing proxy CONNECT responses. This vulnerability can lead to memory exhaustion when a malicious proxy sends oversized headers, potentially causing the Rclone process to crash. This issue impacts FTP and SFTP proxy connections, where the vulnerable parser is engaged prior to SSH server authentication, allowing for a breach even without validating the target host's key. The vulnerability has been addressed in version 1.75.0.

Affected Version(s)

rclone < 1.75.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.