CVE-2026-79782
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.13%
- CWE
- CWE-319
- Published
- 2026-08-25
- Last modified
- 2026-08-28
Affected products
- rclone rclone
- rclone rclone
Weakness type
Related vulnerabilities
- CVE-2026-88013 — rclone: http backend forwards custom/auth headers to a different host on redirect
- CVE-2026-81330 — Softish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive information
- CVE-2026-87482 — Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to...
- CVE-2026-71216 — Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP
- CVE-2026-84381 — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
- CVE-2026-84366 — Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
- CVE-2026-55860 — MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
- CVE-2026-55857 — MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials