Denial of Service Vulnerability in rclone by the Vendor rclone
CVE-2026-79778

6MEDIUM

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79778?

The rclone software, prior to version 1.75.0, is susceptible to a denial of service vulnerability within its WebDAV TUS creation handler. This vulnerability arises from the erroneous dereferencing of a nil response without proper error checks for transport issues. When exploited, a malicious or compromised endpoint can sever connections during TUS uploads, leading to a panic state that terminates unrecovered goroutines. This disruption can halt other essential operations in long-running processes, significantly impacting the software's overall functionality.

Affected Version(s)

rclone 0 < 1.75.0

rclone 1.75.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cyberlanc3r
ncw
.