Security: RsyncProject/rsync
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
rsync: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to blockGHSA-6692-28cx-wpqq published
Aug 13, 2026 by tridgeHigh -
rsync: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chainGHSA-8x5r-mjx8-83hv published
Aug 13, 2026 by tridgeHigh -
rsync: rsync-ssl establishes an unauthenticated TLS connection (no CA verification; no stunnel hostname binding)GHSA-3c3x-ww2w-5r5p published
Aug 13, 2026 by tridgeModerate -
rsync: Peer-controlled Zstandard worker exhaustion on an rsync daemonGHSA-rjvj-qgqg-cvx9 published
Aug 13, 2026 by tridgeHigh -
rsync: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargsGHSA-78jc-79jv-v6rw published
Aug 13, 2026 by tridgeHigh -
rsync: Attacker-chosen-offset write in parse_size_arg() error formattingGHSA-pg7g-xqmr-xpfh published
Aug 13, 2026 by tridgeModerate -
rsync: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -HGHSA-gg3m-4m9m-268h published
Aug 13, 2026 by tridgeHigh -
rsync: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer rootGHSA-p4v4-qxw9-q72m published
Aug 13, 2026 by tridgeModerate -
rsync: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in-module symlinkGHSA-w3xf-j2r2-gv4x published
Aug 13, 2026 by tridgeHigh -
rsync: Peer-driven one-byte heap out-of-bounds write in add_implied_include()GHSA-jhxm-j4mq-3fj4 published
Aug 13, 2026 by tridgeHigh