CVE-2026-70453

rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-13 15:19

Updated : 2026-09-08 20:28


NVD link : CVE-2026-70453

Mitre link : CVE-2026-70453

CVE.ORG link : CVE-2026-70453


JSON object : View

Products Affected

No product.

CWE
CWE-407

Inefficient Algorithmic Complexity