rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and reuse credentials to perform WebDAV operations with the compromised account's permissions.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and reuse credentials to perform WebDAV operations with the compromised account's permissions. | |
| Title | rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect | |
| First Time appeared |
Rclone
Rclone rclone |
|
| Weaknesses | CWE-319 | |
| CPEs | cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rclone
Rclone rclone |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T15:16:09.110Z
Reserved: 2026-08-25T14:32:37.762Z
Link: CVE-2026-79779
No data.
Status : Received
Published: 2026-08-25T16:17:29.807
Modified: 2026-08-25T16:17:29.807
Link: CVE-2026-79779
No data.
OpenCVE Enrichment
Updated: 2026-08-25T18:00:14Z
Weaknesses