rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address. | |
| Title | rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:38:10.300Z
Reserved: 2026-06-10T20:14:32.827Z
Link: CVE-2026-53791
No data.
Status : Received
Published: 2026-08-13T15:19:43.363
Modified: 2026-08-13T15:19:43.363
Link: CVE-2026-53791
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:00:04Z