rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 16:17
Updated : 2026-09-10 20:46
NVD link : CVE-2026-79777
Mitre link : CVE-2026-79777
CVE.ORG link : CVE-2026-79777
JSON object : View
Products Affected
No product.
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
