Improper Neutralization of Special Elements in Output Used by a Downstream Component in Rsync - CVE-2026-53788
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject requests into a persistent helper protocol and disclose sensitive information or modify data.
The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in the name-converter helper when writing peer-controlled names into its persistent line protocol. A remote attacker can supply a name containing a newline or carriage return to inject requests into that channel to disclose sensitive information or modify data.