MEDIUM 6.4 GitHub

CVE-2026-71311

rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines

## 1. Summary A valid but nondefault FTP filename encoding can restore raw CR/LF immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel. The dependency does not reject CR or LF in command arguments, so a filename can inject an independent authenticated command. A real test server observed the injected `DELE` command. The default FTP encoding and the configuration-wizard examples include `Ctl` and are not vulnerable to the demonstrated filename

Affected Products

References

Published: 2026-08-05 · Source: GitHub · Feed updated: 2026-08-05
This medium severity vulnerability with a CVSS score of 6.4 was published on 2026-08-05 via GitHub. Affected: go/github.com/rclone/rclone < 1.75.0.
vulnfeed aggregates 9344 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.