Memory Management Vulnerability in Rclone Cloud Sync Tool by Rclone
CVE-2026-88045
7.5HIGH
What is CVE-2026-88045?
The vulnerability in Rclone's cloud sync functionality arises from improper handling of multipart requests in versions 1.75.0 through 1.75.1. Specifically, the serve S3 component incorrectly allows attacker-controlled content lengths to be processed without adequate verification. This can lead to excessive memory allocation, potentially allowing a malicious user to cause memory exhaustion or disruption to the application's operation. Rclone users are encouraged to upgrade to version 1.75.1 to mitigate these risks.
Affected Version(s)
rclone >= 1.75.0, < 1.75.1
