CRITICAL 9.1 NVD
CVE-2026-53791
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sendi
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address.
References
- https://github.com/RsyncProject/rsync/releases/tag/v3.5.0
- https://github.com/RsyncProject/rsync/security/advisories/GHSA-h2q9-5fr8-w635
- https://www.vulncheck.com/advisories/rsync-daemon-ip-spoofing-via-proxy-protocol-header
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-08-13 via NVD.
Risk Timeline
CVE Disclosed2026-08-13 · -1 days ago
Remediation Resources
vulnfeed aggregates 10617 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.