Insufficiently protected credentials in rclone - #VU140656
Published: August 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to insufficiently protected credentials in the S3 redirect callback when following unsafe redirects that change scheme or host. A remote attacker can induce a redirect that causes IBM IAM bearer tokens or SSE-C key headers to be forwarded to an unintended destination to disclose sensitive information.
The issue affects same-host HTTPS-to-HTTP redirects for IBM IAM bearer authorization and cross-origin redirects for SSE-C and copy-source SSE-C key headers.