Rsync

Vendor:

First CVE: Mar 15, 2002 · Active for 24 years

24
Total CVEs
More Total CVEs than 95% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Rsync over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2002
24 years ago
Most Recent CVE
May 20, 2026
64 days ago

CVE Severity & Scoring

Rsync24 CVEs
All CVEs352,101 CVEs
LowMediumHighCritical
Attack Vector
Local3 (12.5%)
Network16 (66.7%)
Unknown5 (20.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (45.8%)
High8 (33.3%)
Unknown5 (20.8%)
User Interaction
None17 (70.8%)
Unknown5 (20.8%)
Required2 (8.3%)
Privileges Required
Low3 (12.5%)
High0 (0.0%)
None16 (66.7%)
Unknown5 (20.8%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIG
Jan 15, 20259.875NONO
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malici
May 20, 20268.136NONO
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in re
Dec 6, 20179.833NONO
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a
Nov 6, 20179.833NONO
rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync developme
Oct 29, 20179.833NONO
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparis
Jan 14, 20257.532NONO
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended di
May 20, 20267.031NONO
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --
Apr 16, 20267.831NONO
Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync c
May 20, 20266.530NONO
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link
May 20, 20266.329NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Rsync

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.3.019.872.1%00
3.2.719.872.1%00
3.2.017.41.1%00
3.1.213.71.8%00
3.1.116.46.5%00
3.0.917.84.1%00
3.0.817.84.1%00
3.0.726.53.6%00
3.0.626.53.6%00
3.0.526.53.6%00
3.0.426.53.6%00
3.0.326.53.6%00
3.0.226.53.6%00
3.0.136.84.1%00
3.0.036.84.1%00
2.9.927.74.5%00
2.9.827.74.5%00
2.9.727.74.5%00
2.9.627.74.5%00
2.9.527.74.5%00