github.com/rclone/rclone: rclone: Denial of Service via crafted Range request against translated symlink

cve CVE-2026-88015 2 sources, 2 claims · Watch

Red Hat writes:
github.com/rclone/rclone: rclone: Denial of Service via crafted Range request against translated symlink the claim
Severity
MEDIUM NVD
moderate Red Hat
CVSS
5.3 NVD
5.3 Red Hat
Vendor
rclone NVD
Product
rclone NVD
CWE
CWE-190, CWE-248 NVD
CWE-125 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-09-10first spoke of it: rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1.NVD
2026-09-10first spoke of it: github.com/rclone/rclone: rclone: Denial of Service via crafted Range request against translated symlinkRed Hat

What it is to other things

affectsrclone/rclone
NVD
made_byrclone
NVD
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDyes
An attacker can reliably run all of the kill chain's first four steps without a person.
receipt
Source
NVD
Its words
yes
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCyes
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "rclone",
            "vendor": "rclone",
            "versions": [
              {
                "status": "affected",
                "version": "< 1.75.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "FA20072C-EAD0-4F08-B600-F0B5ECDE19D7",
                "versionEndExcluding": "1.75.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1."
      }
    ],
    "id": "CVE-2026-88015",
    "lastModified": "2026-09-23T20:42:27.633",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-88015",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T16:01:29.337669Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-10T16:18:08.490",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/rclone/rclone/releases/tag/v1.75.1"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          },
          {
            "lang": "en",
            "value": "CWE-248"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
CVSS
cvss
NVD5.3
receipt
Source
NVD
Its words
5.3
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "rclone",
            "vendor": "rclone",
            "versions": [
              {
                "status": "affected",
                "version": "< 1.75.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "FA20072C-EAD0-4F08-B600-F0B5ECDE19D7",
                "versionEndExcluding": "1.75.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1."
      }
    ],
    "id": "CVE-2026-88015",
    "lastModified": "2026-09-23T20:42:27.633",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-88015",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T16:01:29.337669Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-10T16:18:08.490",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/rclone/rclone/releases/tag/v1.75.1"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          },
          {
            "lang": "en",
            "value": "CWE-248"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
CVSS
cvss
Red Hat5.3
receipt
Source
Red Hat
Its words
5.3
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-88015",
  "CWE": "CWE-125",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2531541",
  "bugzilla_description": "github.com/rclone/rclone: rclone: Denial of Service via crafted Range request against translated symlink",
  "cvss3_score": "5.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-10T15:50:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-88015.json",
  "severity": "moderate"
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "rclone",
            "vendor": "rclone",
            "versions": [
              {
                "status": "affected",
                "version": "< 1.75.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "FA20072C-EAD0-4F08-B600-F0B5ECDE19D7",
                "versionEndExcluding": "1.75.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1."
      }
    ],
    "id": "CVE-2026-88015",
    "lastModified": "2026-09-23T20:42:27.633",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-88015",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T16:01:29.337669Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-10T16:18:08.490",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/rclone/rclone/releases/tag/v1.75.1"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          },
          {
            "lang": "en",
            "value": "CWE-248"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
Red HatCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
2026-09-29 09:44 UTC—
What the source handed over
{
  "CVE": "CVE-2026-88015",
  "CWE": "CWE-125",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2531541",
  "bugzilla_description": "github.com/rclone/rclone: rclone: Denial of Service via crafted Range request against translated symlink",
  "cvss3_score": "5.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-10T15:50:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-88015.json",
  "severity": "moderate"
}
—
CWE
cwe
different words
NVDCWE-190, CWE-248
receipt
Source
NVD
Its words
CWE-190, CWE-248
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCWE-190, CWE-248
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "rclone",
            "vendor": "rclone",
            "versions": [
              {
                "status": "affected",
                "version": "< 1.75.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "FA20072C-EAD0-4F08-B600-F0B5ECDE19D7",
                "versionEndExcluding": "1.75.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1."
      }
    ],
    "id": "CVE-2026-88015",
    "lastModified": "2026-09-23T20:42:27.633",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-88015",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T16:01:29.337669Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-10T16:18:08.490",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/rclone/rclone/releases/tag/v1.75.1"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          },
          {
            "lang": "en",
            "value": "CWE-248"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
CWE
cwe
different words
Red HatCWE-125
receipt
Source
Red Hat
Its words
CWE-125
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-88015",
  "CWE": "CWE-125",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2531541",
  "bugzilla_description": "github.com/rclone/rclone: rclone: Denial of Service via crafted Range request against translated symlink",
  "cvss3_score": "5.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-10T15:50:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-88015.json",
  "severity": "moderate"
}
—
Exploitation
exploitation
NVDpoc
A public proof of concept exists, or exploitation is trivial.
receipt
Source
NVD
Its words
poc
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCpoc
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "rclone",
            "vendor": "rclone",
            "versions": [
              {
                "status": "affected",
                "version": "< 1.75.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "FA20072C-EAD0-4F08-B600-F0B5ECDE19D7",
                "versionEndExcluding": "1.75.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1."
      }
    ],
    "id": "CVE-2026-88015",
    "lastModified": "2026-09-23T20:42:27.633",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-88015",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T16:01:29.337669Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-10T16:18:08.490",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/rclone/rclone/releases/tag/v1.75.1"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          },
          {
            "lang": "en",
            "value": "CWE-248"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Product
product
NVDrclone
receipt
Source
NVD
Its words
rclone
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCrclone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "rclone",
            "vendor": "rclone",
            "versions": [
              {
                "status": "affected",
                "version": "< 1.75.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "FA20072C-EAD0-4F08-B600-F0B5ECDE19D7",
                "versionEndExcluding": "1.75.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1."
      }
    ],
    "id": "CVE-2026-88015",
    "lastModified": "2026-09-23T20:42:27.633",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-88015",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T16:01:29.337669Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-10T16:18:08.490",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/rclone/rclone/releases/tag/v1.75.1"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          },
          {
            "lang": "en",
            "value": "CWE-248"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCMEDIUM
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "rclone",
            "vendor": "rclone",
            "versions": [
              {
                "status": "affected",
                "version": "< 1.75.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "FA20072C-EAD0-4F08-B600-F0B5ECDE19D7",
                "versionEndExcluding": "1.75.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1."
      }
    ],
    "id": "CVE-2026-88015",
    "lastModified": "2026-09-23T20:42:27.633",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-88015",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T16:01:29.337669Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-10T16:18:08.490",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/rclone/rclone/releases/tag/v1.75.1"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          },
          {
            "lang": "en",
            "value": "CWE-248"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
medium
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-88015",
  "CWE": "CWE-125",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2531541",
  "bugzilla_description": "github.com/rclone/rclone: rclone: Denial of Service via crafted Range request against translated symlink",
  "cvss3_score": "5.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-10T15:50:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-88015.json",
  "severity": "moderate"
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "rclone",
            "vendor": "rclone",
            "versions": [
              {
                "status": "affected",
                "version": "< 1.75.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "FA20072C-EAD0-4F08-B600-F0B5ECDE19D7",
                "versionEndExcluding": "1.75.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1."
      }
    ],
    "id": "CVE-2026-88015",
    "lastModified": "2026-09-23T20:42:27.633",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-88015",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T16:01:29.337669Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-10T16:18:08.490",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/rclone/rclone/releases/tag/v1.75.1"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          },
          {
            "lang": "en",
            "value": "CWE-248"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCpartial
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "rclone",
            "vendor": "rclone",
            "versions": [
              {
                "status": "affected",
                "version": "< 1.75.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "FA20072C-EAD0-4F08-B600-F0B5ECDE19D7",
                "versionEndExcluding": "1.75.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1."
      }
    ],
    "id": "CVE-2026-88015",
    "lastModified": "2026-09-23T20:42:27.633",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-88015",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T16:01:29.337669Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-10T16:18:08.490",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/rclone/rclone/releases/tag/v1.75.1"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          },
          {
            "lang": "en",
            "value": "CWE-248"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Vendor
vendor
NVDrclone
receipt
Source
NVD
Its words
rclone
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCrclone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "rclone",
            "vendor": "rclone",
            "versions": [
              {
                "status": "affected",
                "version": "< 1.75.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "FA20072C-EAD0-4F08-B600-F0B5ECDE19D7",
                "versionEndExcluding": "1.75.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1."
      }
    ],
    "id": "CVE-2026-88015",
    "lastModified": "2026-09-23T20:42:27.633",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-88015",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T16:01:29.337669Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-10T16:18:08.490",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/rclone/rclone/releases/tag/v1.75.1"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          },
          {
            "lang": "en",
            "value": "CWE-248"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

github.com/rclone/rclone: rclone: Denial of Service via crafted Range request against translated symlink
zetlyn/cve-redhat · 2026-09-10
cvss 5.3 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L cwe CWE-125 severity moderate source
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1.
zetlyn/cve-nvd · 2026-09-10
automatable yes cvss 5.3 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L cwe CWE-190, CWE-248 exploitation poc product rclone severity MEDIUM status Analyzed technical_impact partial vendor rclone source