Cleartext transmission of sensitive information in rclone - #VU140655
Published: August 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to cleartext transmission of sensitive information in the WebDAV redirect handling logic when following a same-host HTTPS-to-HTTP redirect. A remote attacker can observe the plaintext hop to disclose sensitive information.
Exploitation requires a legitimate endpoint, gateway, or accelerator to emit the unsafe redirect.