Input validation error in Rsync - CVE-2026-53789
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the rsync receiver file-list handling when processing file-list entries from a malicious sender under --delete or --force. A remote attacker can send crafted transfer-root or implied-parent entries to cause a denial of service.
User interaction is required to initiate a transfer from a malicious sender.