HTTP Header Exposure Vulnerability in Rclone by Rclone
CVE-2026-88013
3.7LOW
What is CVE-2026-88013?
A vulnerability in Rclone allows sensitive HTTP headers, such as API keys and authorization tokens, to be inadvertently exposed during operations. This issue occurs when the Rclone HTTP backend handles redirects without proper checks, leading to the potential leakage of custom secrets to untrusted servers. Users conducting operations like listing or downloading files could inadvertently send sensitive information in cleartext, especially in cases of same-host HTTP to HTTPS redirects. The vulnerability has been resolved in Rclone version 1.75.1.
Affected Version(s)
rclone >= 1.49.0, < 1.75.1
