CVE-2026-79780
rclone before 1.75.0: credential exposure on redirect, WebDAV TUS DoS panic, and RC API stack-trace disclosure
- Severity
- medium
- Affected product
- rclone
- Affected versions
- rclone < 1.75.0
- Fixed in
- rclone 1.75.0
- Added to NewScan
- 2026-08-26
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints rclone from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-26 (/daily-cve). Same version source as the rclone rows above. Four advisories share the 1.75.0 fix, so one version-gated finding avoids duplicate upgrade advice (the exceljs-hardened precedent): CVE-2026-79780 preserves IBM IAM bearer tokens and SSE-C keys across an S3 redirect scheme/host change; CVE-2026-79779 replays Basic auth and Cookie headers over plaintext HTTP after a redirect downgrade; CVE-2026-79778 panics on a nil response in the WebDAV TUS creation handler (DoS); CVE-2026-79777 returns full Go stack traces from the RC API on panic (path/module/goroutine disclosure). Version-match only - none is safely provable against a live customer, and the banner in range is the shared signal. The related rclone < 1.75.0 pprof auth bypass (CVE-2026-79776) is not here: it is anonymously observable and already detected by the Go pprof exposure row, cited there.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →