rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and reuse credentials to perform WebDAV operations with the compromised account's permissions.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 16:17
Updated : 2026-09-10 20:46
NVD link : CVE-2026-79779
Mitre link : CVE-2026-79779
CVE.ORG link : CVE-2026-79779
JSON object : View
Products Affected
No product.
CWE
CWE-319
Cleartext Transmission of Sensitive Information
