Allocation of Resources Without Limits or Throttling in rclone - #VU140653
Published: August 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the HTTP CONNECT helper when parsing proxy CONNECT responses. A remote attacker can send a crafted proxy response with excessively large headers to cause a denial of service.
This issue affects configured malicious or compromised proxies, and active on-path actors only for plaintext HTTP proxy connections.