Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an attacker who can manipulate a parent directory of the source tree to redirect file reads to unintended paths. Attackers can atomically replace a parent directory component with a symlink pointing outside the source root between path resolution and file open operations to disclose file contents outside the intended transfer root. | |
| Title | rsync < 3.5.0 Symlink Race Condition Information Disclosure | |
| Weaknesses | CWE-367 CWE-59 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T17:38:35.788Z
Reserved: 2026-06-10T20:14:32.828Z
Link: CVE-2026-53797
No data.
Status : Received
Published: 2026-08-13T15:19:51.750
Modified: 2026-08-13T15:19:51.750
Link: CVE-2026-53797
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:00:04Z