rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-13 15:19
Updated : 2026-09-08 20:28
NVD link : CVE-2026-70453
Mitre link : CVE-2026-70453
CVE.ORG link : CVE-2026-70453
JSON object : View
Products Affected
No product.
CWE
CWE-407
Inefficient Algorithmic Complexity
