Allocation of Resources Without Limits or Throttling in Rsync - CVE-2026-70455
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the rsync daemon sender when processing a PULL request with a large --compress-threads value. A remote attacker can send a request that names a large worker count to cause a denial of service.
A stock client is sufficient, and no crafted protocol is required. On anonymous modules, no authentication is required.