Rclone
25 CVEs tracked since 2026. Since Aug 2026, none of them reached CISA KEV.
Rclone CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-08 | 14 | 0 |
| 2026-09 | 11 | 0 |
Products
The products that kept showing up in Rclone's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Rclone.
- CVE-2026-93987rclone serve docker Path Traversal via Volume Name3.4
- CVE-2026-93986rclone before 1.75.1 Path Traversal via Directory Listing Names3.1
- CVE-2026-88046rclone: source object names can escape the configured root on upload5.3
- CVE-2026-88045rclone: S3 multipart declared-length memory exhaustion7.5
- CVE-2026-88044rclone: RC per-server auth-proxy bypass9.1
- CVE-2026-88018rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass9.8
- CVE-2026-88017rclone: FTP cross-session auth-proxy backend confusion7.3
- CVE-2026-88016rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination7.1
- CVE-2026-88015rclone local: crafted Range request against a translated symlink panics (DoS)5.3
- CVE-2026-88014rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace6.3
- CVE-2026-88013rclone: http backend forwards custom/auth headers to a different host on redirect3.7
- CVE-2026-79783rclone before 1.74.4 Privilege Escalation via setuid Metadata3.6
- CVE-2026-79782rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect3.1
- CVE-2026-79781rclone serve s3 Path Traversal via dot-dot object keys6.5
- CVE-2026-79779rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect5.3
The record
- Peak rank
- #113 in Sep 2026
- Busiest month shown
- Aug 2026, 14 CVEs
- Months with a KEV entry
- 0 since Aug 2026
- Monthly snapshots
- 2 since 2026