Not Failing Securely ('Failing Open') in Rsync - CVE-2026-70452
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass host-based access restrictions and gain unauthorized access.
The vulnerability exists due to not failing securely in hosts deny access control processing when performing a forward DNS lookup of a configured hostname token. A remote attacker can connect from a host that should be denied to bypass host-based access restrictions and gain unauthorized access.
The issue occurs when forward lookup is enabled and a hostname token in hosts deny cannot be resolved, including during transient resolver failures or when a global daemon chroot lacks resolver configuration.