← All CVEs NewScan detects
critical

CVE-2026-79782

rclone S3 backend leaks the X-Amz-Security-Token over plaintext HTTP on an HTTPS->HTTP redirect

Severity
critical
Affected product
rclone
Affected versions
rclone < 1.74.4
Fixed in
rclone 1.74.4
Added to NewScan
2026-08-26
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints rclone from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-26 (/daily-cve). Version source is the rclone fingerprint's own Server banner - the tech_signatures header.server row `rclone/v(\d+...)`, measured 2026-08-23 to ride EVERY response (listings and errors alike), so techdb.detect stamps the version inline and this key joins with no version_from. rclone before 1.74.4 fails to strip X-Amz-Security-Token when an S3 redirect downgrades HTTPS to HTTP on the same host, disclosing the session token in cleartext (vulncheck advisory, GHSA-gx4c-2hqx-cw2r). Version-match only: the leak needs an attacker-positioned redirect and MITM path we will not stage against a customer, so a banner in range means `vulnerable build`, not `confirmed intercepted`.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →