CVE-2026-79782
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rclone | rclone | 0 < 1.74.4 | affected |
| rclone | rclone | 1.74.4 | unaffected |
Weaknesses
- CWE-319: Cleartext Transmission of Sensitive Information
References
- https://github.com/rclone/rclone/security/advisories/GHSA-gx4c-2hqx-cw2r
- https://www.vulncheck.com/advisories/rclone-before-security-token-disclosure-via-https-to-http-redirect
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.