CVE-2026-79782

NameCVE-2026-79782
Descriptionrclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1145670

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rclone (PTS)bullseye1.53.3-1vulnerable
bookworm1.60.1+dfsg-2vulnerable
trixie1.60.1+dfsg-4vulnerable
sid1.69.3+dfsg-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rclonesource(unstable)(unfixed)1145670

Notes

https://github.com/rclone/rclone/security/advisories/GHSA-gx4c-2hqx-cw2r

Search for package or bug name: Reporting problems