These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-70464 is a denial-of-service vulnerability in rsync daemon versions 2.0.0 before 3.5.0. Unaffected and affected users should assess exposure and prioritize upgrading to version 3.5.0 or later to prevent potential service disruption caused by exhausting daemon connection slots through stalling the handshake process. System administrators and security teams must verify exposure and consider the pot [truncated]
The CVE-2026-70463 record indicates an authorization bypass in rsync's auth users directive parsing. The issue arises from comma-only tokenization, which fails to handle group names with spaces correctly, potentially allowing unauthorized access to restricted modules. This vulnerability affects rsync versions before 3.5.0 and is classified as HIGH severity with a CVSS score of 8.6. To verify and mitigate, [truncated]
CVE-2026-70462 is a HIGH severity vulnerability in rsync versions 3.1.0 before 3.5.0. Attackers can disable connection timeouts by injecting malicious MSG_IO_TIMEOUT messages, potentially leading to resource exhaustion. System administrators and security teams should assess exposure and prioritize upgrading to version 3.5.0 or later. The vulnerability exists in the I/O timeout implementation, allowing att [truncated]
The CVE-2026-70461 vulnerability is a heap out-of-bounds write issue in rsync versions before 3.5.0. This allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. The vulnerability can be triggered against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing b [truncated]
CVE-2026-70460 is a critical path traversal vulnerability in rsync versions before 3.5.0. A malicious sender can exploit symlinks within the module file tree when using --partial-dir or --backup-dir options to write files outside the intended module root. This vulnerability has a CVSS score of 9.2 and is considered CRITICAL. System administrators and security teams should assess exposure and prioritize up [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T15:19:59.813Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects rsync versions 3.0.0 before 3.5.0, allowing remote attackers to crash the daemon by sending a file list with a dot entry not typed as a directory. The vulnerability is caus [truncated]
CVE-2026-70458 is an out-of-bounds write vulnerability in rsync versions before 3.5.0. The vulnerability allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. This issue is caused by the missing F_SUM field in the file_struct layout, which enables attackers to access memory past the end of [truncated]
The CVE-2026-70457 vulnerability is an out-of-bounds write issue in the parse_size_arg() function of rsync versions 3.2.3 before 3.5.0. This occurs when the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. If snprintf truncates the formatted size string, the return value may exceed the array length, leading to memory corruption outside the intended [truncated]
CVE-2026-70456 is an out-of-bounds write vulnerability in rsync's read_args() function. A malicious sender can corrupt adjacent heap memory by sending a crafted argument list, potentially leading to security consequences. The vulnerability affects rsync versions before 3.5.0. This issue is particularly concerning for defenders responsible for rsync deployments, especially in environments exposed to untrus [truncated]
The CVE-2026-70455 vulnerability affects rsync versions 3.4.2 and earlier, allowing a remote attacker to cause a denial of service by specifying the --zt option with a large value, which spawns an unbounded number of Zstandard worker threads, exhausting available thread and memory resources. System administrators and security teams should be aware of this vulnerability and take steps to mitigate it. The v [truncated]
A TLS certificate validation vulnerability exists in rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode). This vulnerability allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. The client fails to validate server TLS certificates against a trusted CA or verify certificate hostname matching, enabling attackers [truncated]
CVE-2026-70453 is an algorithmic complexity vulnerability in rsync's hash_search() function, allowing a remote attacker to cause a denial of service by delivering a crafted file list, which can exhaust receiver CPU resources. This vulnerability affects rsync deployments, and defenders should assess exposure and prioritize verification and remediation to prevent sustained denial of service. The vulnerabili [truncated]
CVE-2026-70452 is a critical access control bypass vulnerability in rsync versions before 3.5.0. Remote attackers can exploit this vulnerability by inducing DNS resolution failures during hostname-based access control evaluation, allowing them to bypass module-level IP access controls and gain unauthorized access to restricted module file trees. This vulnerability affects rsync installations and requires [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T15:19:53.020Z and has not been modified since then. The rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics pat [truncated]
The rsync utility before version 3.5.0 is vulnerable to an arbitrary file read attack due to improper handling of symlinks in configuration files. This vulnerability allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling, including --files-from, --password-file, and filter merge files. System administrators and security te [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T15:19:52.623Z and has not been modified since then. CVE-2026-53801 is a HIGH severity vulnerability in rsync versions before 3.5.0, allowing attackers to cause the sender to enumerate and transfer files outside the module root's intended subtree through a symlink race condition in the sender's di [truncated]
The CVE-2026-53800 vulnerability is classified as a symlink race condition issue within the --remove-source-files feature of rsync versions prior to 3.5.0. This vulnerability allows attackers with symlink creation access to cause arbitrary file deletion. The issue arises when an attacker can atomically substitute a symlink for a source file between the completion of the transfer and the unlink() call, lea [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T15:19:52.130Z and has not been modified since then. This CVE-2026-53799 vulnerability exists in rsync before version 3.5.0 and involves a symlink race condition that allows local attackers to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictabl [truncated]
The rsync utility before version 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping. This allows local attackers to influence name-converter responses to return empty values, causing rsync to incorrectly interpret them as successful resolutions to uid/gid 0 (root). Consequently, if the name-converter also signals fake super-user status, rsync proceeds with [truncated]
The CVE-2026-53797 vulnerability is a symlink race condition in rsync before version 3.5.0. This vulnerability allows an attacker to manipulate a parent directory of the source tree to redirect file reads to unintended paths, potentially disclosing file contents outside the intended transfer root. The vulnerability occurs when an attacker can atomically replace a parent directory component with a symlink [truncated]
CVE-2026-53796 is a time-of-check to time-of-use (TOCTOU) race condition vulnerability in rsync before version 3.5.0. The vulnerability allows an attacker to redirect file writes to unintended locations by manipulating destination path parent components. This can occur when an attacker substitutes a symlink for a component of the destination path between the path resolution and chdir() call, causing the r [truncated]
The CVE-2026-53795 vulnerability in rsync allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. This is due to a bypass of the rename-confinement logic when these options resolve to paths outside the destination tree. The vulnerability affects rsync versions before 3.5.0 and has a high CVSS score of 7.2. System administr [truncated]
CVE-2026-53794 debrief based on the supplied source corpus. The rsync utility before version 3.5.0 contains a logic error in --max-alloc handling, allowing potential denial-of-service attacks through unbounded memory allocations. This flaw can cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory. Defenders should assess expos [truncated]
CVE-2026-53793 debrief: The rsync path confinement bypass vulnerability allows remote clients to escape the intended inner-module root confinement, potentially leading to unauthorized file access. This vulnerability affects rsync deployments, and defenders should assess exposure and verify configurations to prevent unauthorized file access. The vulnerability is caused by improper handling of the /./ notat [truncated]
CVE-2026-53792 is an out-of-bounds read vulnerability in rsync before version 3.5.0. A malicious receiver can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side. This vulnerability has a high severity and defenders should prioritize verificatio [truncated]
The CVE-2026-53791 record indicates an IP address spoofing vulnerability in rsync daemon before version 3.5.0, allowing unauthenticated remote attackers to bypass IP-based access controls. This vulnerability can be exploited by attackers who can connect directly to the rsync daemon, allowing them to inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unaut [truncated]
CVE-2026-53790 is a critical vulnerability in rsync versions before 3.5.0, allowing attackers to execute arbitrary commands via multiple code paths. The vulnerability has a CVSS score of 9.2 and is classified as CRITICAL. System administrators and security teams should assess exposure and prioritize remediation based on their specific environments and configurations. This vulnerability affects rsync servi [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T15:19:43.030Z and has not been modified since then. The CVE-2026-53789 vulnerability affects rsync versions before 3.5.0, allowing a malicious sender to expand the scope of --delete operations beyond the intended destination subtree. This can be exploited through multiple variants, including impl [truncated]
A newline injection vulnerability exists in rsync versions before 3.5.0 in the name-converter uid/gid mapping interface. This allows local attackers to forge protocol messages by creating user or group names containing newline characters, potentially corrupting uid/gid mapping logic. The vulnerability has a medium severity and is addressed in rsync version 3.5.0. System administrators and security teams s [truncated]
The rsync filter rule bypass vulnerability (CVE-2026-53786) affects rsync versions before 3.5.0, allowing authenticated clients to inject malicious --filter merge file directives and override module-level filter restrictions. This MEDIUM-severity vulnerability has a CVSS score of 6.9 and can lead to unauthorized access to files intended to be excluded. System administrators and security teams should be aw [truncated]