CVE-2026-79782
rclone S3 backend leaks the X-Amz-Security-Token over plaintext HTTP on an HTTPS->HTTP redirect
- Severity
- critical
- Affected product
- rclone
- Affected versions
- rclone < 1.74.4
- Fixed in
- rclone 1.74.4
- Added to NewScan
- 2026-08-26
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints rclone from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-26 (/daily-cve). Version source is the rclone fingerprint's own Server banner - the tech_signatures header.server row `rclone/v(\d+...)`, measured 2026-08-23 to ride EVERY response (listings and errors alike), so techdb.detect stamps the version inline and this key joins with no version_from. rclone before 1.74.4 fails to strip X-Amz-Security-Token when an S3 redirect downgrades HTTPS to HTTP on the same host, disclosing the session token in cleartext (vulncheck advisory, GHSA-gx4c-2hqx-cw2r). Version-match only: the leak needs an attacker-positioned redirect and MITM path we will not stage against a customer, so a banner in range means `vulnerable build`, not `confirmed intercepted`.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →