Transport Downgrade Vulnerability in rclone by rclone
CVE-2026-79779
6MEDIUM
What is CVE-2026-79779?
Versions of rclone prior to v1.75.0 contain a vulnerability that allows attackers to exploit transport downgrades during redirect handling. This flaw enables the unauthorized replay of Basic authorization and Cookie headers over plaintext HTTP following HTTPS-to-HTTP redirects within the same host. An on-path attacker can intercept this insecure traffic to capture and reuse sensitive credentials, potentially gaining unauthorized access to WebDAV operations using the compromised account's permissions.
Affected Version(s)
rclone 0 < 1.75.0
rclone 1.75.0
