Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-79782: rclone up to 1.74.3 may leak AWS token

CVE-2026-79782 · published today
Summary

The rclone tool (versions before 1.74.4) can mistakenly include an AWS security token in requests that are redirected from a secure HTTPS link to an unencrypted HTTP link on the same server. This lets anyone who can view the plain‑text traffic capture the token and potentially access your AWS resources. Upgrade rclone to version 1.74.4 or later, or ensure redirects never switch from HTTPS to HTTP.

What to do
  • Update rclone to version 1.74.4.
  • Update rclone rclone to version 1.74.4 or later.
Affected software
Ecosystem VendorProductAffected versions
– rclone rclone < 1.74.4
Debian:11 debian rclone All versions
Debian:12 debian rclone All versions
Debian:13 debian rclone All versions
Bitnami – rclone < 1.74.4
Fix: upgrade to 1.74.4
Original advisory text
rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.
Severity
9.3 Critical
CVSS 3.1: 3.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-319Cleartext Transmission of Sensitive Information
Timeline
Published25 Sep 2026
Updated25 Sep 2026
First seen25 Aug 2026
Track software like this
Free during beta