HTTP Header Exposure Vulnerability in Rclone by Rclone
CVE-2026-88013

3.7LOW

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88013?

A vulnerability in Rclone allows sensitive HTTP headers, such as API keys and authorization tokens, to be inadvertently exposed during operations. This issue occurs when the Rclone HTTP backend handles redirects without proper checks, leading to the potential leakage of custom secrets to untrusted servers. Users conducting operations like listing or downloading files could inadvertently send sensitive information in cleartext, especially in cases of same-host HTTP to HTTPS redirects. The vulnerability has been resolved in Rclone version 1.75.1.

Affected Version(s)

rclone >= 1.49.0, < 1.75.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.