Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-79782: rclone up to 1.74.3 may leak AWS token
CVE-2026-79782 · published today
Summary
The rclone tool (versions before 1.74.4) can mistakenly include an AWS security token in requests that are redirected from a secure HTTPS link to an unencrypted HTTP link on the same server. This lets anyone who can view the plain‑text traffic capture the token and potentially access your AWS resources. Upgrade rclone to version 1.74.4 or later, or ensure redirects never switch from HTTPS to HTTP.
What to do
- Update rclone to version 1.74.4.
- Update rclone rclone to version 1.74.4 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | rclone | rclone | < 1.74.4 |
| Debian:11 | debian | rclone | All versions |
| Debian:12 | debian | rclone | All versions |
| Debian:13 | debian | rclone | All versions |
| Bitnami | – | rclone |
< 1.74.4 Fix: upgrade to 1.74.4
|
Original advisory text
rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.
References
Severity
9.3
Critical
CVSS 3.1: 3.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-319Cleartext Transmission of Sensitive Information
Timeline
Published25 Sep 2026
Updated25 Sep 2026
First seen25 Aug 2026
Sources
CVE-2026-79782 · NVD
CVE-2026-79782 · MITRE
DEBIAN-CVE-2026-79782 · OSV
BIT-rclone-2026-79782 · OSV
Track software like this
Free during beta