CVE-2026-79782

critical

Description

rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.

References

https://www.vulncheck.com/advisories/rclone-before-security-token-disclosure-via-https-to-http-redirect

https://github.com/rclone/rclone/security/advisories/GHSA-gx4c-2hqx-cw2r

Details

Source: Mitre, NVD

Published: 2026-08-25

Updated: 2026-08-25

Risk Information

CVSS v2

Base Score: 1.8

Vector: CVSS2#AV:A/AC:H/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 3.1

Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Low

CVSS v4

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.00132