MEDIUM 5.1 NVD
CVE-2026-79777
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, modul
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
References
- https://github.com/rclone/rclone/security/advisories/GHSA-gwfq-86j8-7qhv
- https://www.vulncheck.com/advisories/rclone-before-information-disclosure-via-rc-api
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-08-25 via NVD.
vulnfeed aggregates 11954 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.