Authentication Bypass by Spoofing in Rsync - CVE-2026-53791
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass host-based access control and spoof the daemon\'s source address.
The vulnerability exists due to authentication bypass by spoofing in PROXY-protocol mode when handling a direct client connection with a supplied PROXY header. A remote attacker can send a forged PROXY header to bypass host-based access control and spoof the daemon\'s source address.
The issue occurs when proxy protocol = true is enabled and the client connects directly rather than through a trusted proxy.