๐Ÿ” CVE Alert

CVE-2026-79779

MEDIUM 5.3

rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and reuse credentials to perform WebDAV operations with the compromised account's permissions.

CWE CWE-319
Vendor rclone
Product rclone
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for rclone rclone

Be the first to know when new medium vulnerabilities affecting rclone rclone are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

rclone / rclone
0 < 1.75.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/rclone/rclone/security/advisories/GHSA-h4mf-4v27-hggj vulncheck.com: https://www.vulncheck.com/advisories/rclone-before-webdav-credential-exposure-via-https-to-http-redirect

Credits

๐Ÿ” cyberlanc3r ncw