Information disclosure in rclone - #VU147303
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper redirect handling in the HTTP backend when following redirects to a different host. A remote attacker can cause a configured remote to redirect requests to another host to disclose sensitive information.
Configured custom headers can be forwarded to a different host, and Authorization and Cookie headers may be transmitted in cleartext following an HTTPS-to-HTTP redirect to the same host.