← All CVEs NewScan detects
medium

CVE-2026-79780

rclone before 1.75.0: credential exposure on redirect, WebDAV TUS DoS panic, and RC API stack-trace disclosure

Severity
medium
Affected product
rclone
Affected versions
rclone < 1.75.0
Fixed in
rclone 1.75.0
Added to NewScan
2026-08-26
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints rclone from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-26 (/daily-cve). Same version source as the rclone rows above. Four advisories share the 1.75.0 fix, so one version-gated finding avoids duplicate upgrade advice (the exceljs-hardened precedent): CVE-2026-79780 preserves IBM IAM bearer tokens and SSE-C keys across an S3 redirect scheme/host change; CVE-2026-79779 replays Basic auth and Cookie headers over plaintext HTTP after a redirect downgrade; CVE-2026-79778 panics on a nil response in the WebDAV TUS creation handler (DoS); CVE-2026-79777 returns full Go stack traces from the RC API on panic (path/module/goroutine disclosure). Version-match only - none is safely provable against a live customer, and the banner in range is the shared signal. The related rclone < 1.75.0 pprof auth bypass (CVE-2026-79776) is not here: it is anonymously observable and already detected by the Go pprof exposure row, cited there.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →