<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:39:02 +0000</lastBuildDate>
    <item>
      <title>BIT-rclone-2026-59733 — rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overw…</title>
      <link>https://cve.radiocsirt.org/vuln/bit-rclone-2026-59733</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: rclone&lt;/p&gt;
&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user&amp;#39;s private repository on backends that clean path components. This issue is fixed in version 1.74.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: rclone&lt;/p&gt;
&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user&amp;#39;s private repository on backends that clean path components. This issue is fixed in version 1.74.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-rclone-2026-59733</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1125 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</link>
      <description>certfr-2026-avi-1125</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</guid>
    </item>
    <item>
      <title>EUVD-2026-342515</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342515</link>
      <description>EUVD-2026-342515</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342515</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59733</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59733</link>
      <description>&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user&amp;#39;s private repository on backends that clean path components. This issue is fixed in version 1.74.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user&amp;#39;s private repository on backends that clean path components. This issue is fixed in version 1.74.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59733</guid>
    </item>
    <item>
      <title>GHSA-fqj9-69pf-6pjg — rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overw…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fqj9-69pf-6pjg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rclone/rclone&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`rclone serve restic --private-repos` exists to let one rclone instance host many users&amp;#39; restic backup repositories behind HTTP Basic auth while keeping each user confined to a path prefix of `/&amp;lt;username&amp;gt;/`. The documentation states the flag &amp;#34;can be used to limit users to repositories starting with a path of `/&amp;lt;username&amp;gt;/`&amp;#34;, and the shipped test `TestResticPrivateRepositories` asserts that user `test` may reach `/test/config` but is `403`-blocked from `/other_user/config`. This isolation is the entire security purpose of the flag.&lt;/p&gt;
&lt;p&gt;The isolation is enforced by two independent chi middlewares that derive the username and the backend object path from two *different* sources, and the path source is never canonicalized. `checkPrivate` authorizes the request by comparing the routed `{userID}` path segment against the authenticated user, while `WithRemote` builds the backend object key from the raw, un-cleaned URL path. A request such as `GET /&amp;lt;me&amp;gt;/../&amp;lt;victim&amp;gt;/config` keeps the first path segment equal to the attacker&amp;#39;s own username (so `checkPrivate` returns the request as authorized) yet hands the backend the literal remote `me/../victim/config`. On any backend that resolves object paths with POSIX `path.Join`/`path.Clean` semantics — which includes the bundled `memory` backend used in the PoC below, and the widely deployed `sftp` and `ftp` backends — that `..` segment collapses, and the operation is performed against the victim&amp;#39;s object.&lt;/p&gt;
&lt;p&gt;Because the same un-cleaned…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rclone/rclone&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`rclone serve restic --private-repos` exists to let one rclone instance host many users&amp;#39; restic backup repositories behind HTTP Basic auth while keeping each user confined to a path prefix of `/&amp;lt;username&amp;gt;/`. The documentation states the flag &amp;#34;can be used to limit users to repositories starting with a path of `/&amp;lt;username&amp;gt;/`&amp;#34;, and the shipped test `TestResticPrivateRepositories` asserts that user `test` may reach `/test/config` but is `403`-blocked from `/other_user/config`. This isolation is the entire security purpose of the flag.&lt;/p&gt;
&lt;p&gt;The isolation is enforced by two independent chi middlewares that derive the username and the backend object path from two *different* sources, and the path source is never canonicalized. `checkPrivate` authorizes the request by comparing the routed `{userID}` path segment against the authenticated user, while `WithRemote` builds the backend object key from the raw, un-cleaned URL path. A request such as `GET /&amp;lt;me&amp;gt;/../&amp;lt;victim&amp;gt;/config` keeps the first path segment equal to the attacker&amp;#39;s own username (so `checkPrivate` returns the request as authorized) yet hands the backend the literal remote `me/../victim/config`. On any backend that resolves object paths with POSIX `path.Join`/`path.Clean` semantics — which includes the bundled `memory` backend used in the PoC below, and the widely deployed `sftp` and `ftp` backends — that `..` segment collapses, and the operation is performed against the victim&amp;#39;s object.&lt;/p&gt;
&lt;p&gt;Because the same un-cleaned…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fqj9-69pf-6pjg</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11241-1 — rclone-1.74.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11241-1</link>
      <description>&lt;p&gt;rclone-1.74.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rclone-1.74.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11241-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59733</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59733</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: rclone, Ubuntu:Pro:20.04:LTS: rclone, Ubuntu:Pro:22.04:LTS: rclone, Ubuntu:Pro:24.04:LTS: rclone, Ubuntu:Pro:26.04:LTS: rclone&lt;/p&gt;
&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user&amp;#39;s private repository on backends that clean path components. This issue is fixed in version 1.74.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: rclone, Ubuntu:Pro:20.04:LTS: rclone, Ubuntu:Pro:22.04:LTS: rclone, Ubuntu:Pro:24.04:LTS: rclone, Ubuntu:Pro:26.04:LTS: rclone&lt;/p&gt;
&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user&amp;#39;s private repository on backends that clean path components. This issue is fixed in version 1.74.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59733</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2266 — rclone: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2266</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um beliebige Dateien zu lesen und zu schreiben, sowie Informationen offenzulegen und Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um beliebige Dateien zu lesen und zu schreiben, sowie Informationen offenzulegen und Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2266</guid>
    </item>
  </channel>
</rss>
