CVE 6.3 MEDIUM

Rsync < 3.4.3 Authorization Bypass via Hostname Resolution_CVE-2026-43617

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Description

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.

Basic Information

ID CVE-2026-43617
Source VulnCheck
Published May 20, 2026 at 00:52

Affected Product

Vendor RsyncProject
Product rsync
Affected Versions RsyncProject rsync 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.