Rsync
Vendor:
First CVE: Mar 15, 2002 · Active for 24 years
24
Total CVEs
More Total CVEs than 95% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rsync over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2002
24 years ago
Most Recent CVE
May 20, 2026
64 days ago
CVE Severity & Scoring
Rsync24 CVEs
13%
25%
46%
17%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (12.5%)
Network16 (66.7%)
Unknown5 (20.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (45.8%)
High8 (33.3%)
Unknown5 (20.8%)
User Interaction
None17 (70.8%)
Unknown5 (20.8%)
Required2 (8.3%)
Privileges Required
Low3 (12.5%)
High0 (0.0%)
None16 (66.7%)
Unknown5 (20.8%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-12084CRITICAL A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIG | Jan 15, 2025 | 9.8 | 75 | NO | NO |
CVE-2026-43618HIGH Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malici | May 20, 2026 | 8.1 | 36 | NO | NO |
CVE-2017-17434CRITICAL The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in re | Dec 6, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-16548CRITICAL The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a | Nov 6, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-15994CRITICAL rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync developme | Oct 29, 2017 | 9.8 | 33 | NO | NO |
CVE-2024-12085HIGH A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparis | Jan 14, 2025 | 7.5 | 32 | NO | NO |
CVE-2026-29518HIGH Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended di | May 20, 2026 | 7.0 | 31 | NO | NO |
CVE-2026-41035HIGH In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka -- | Apr 16, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-43620MEDIUM Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync c | May 20, 2026 | 6.5 | 30 | NO | NO |
CVE-2026-43619MEDIUM Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link | May 20, 2026 | 6.3 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Rsync
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.3.0 | 1 | 9.8 | 72.1% | 0 | 0 |
| 3.2.7 | 1 | 9.8 | 72.1% | 0 | 0 |
| 3.2.0 | 1 | 7.4 | 1.1% | 0 | 0 |
| 3.1.2 | 1 | 3.7 | 1.8% | 0 | 0 |
| 3.1.1 | 1 | 6.4 | 6.5% | 0 | 0 |
| 3.0.9 | 1 | 7.8 | 4.1% | 0 | 0 |
| 3.0.8 | 1 | 7.8 | 4.1% | 0 | 0 |
| 3.0.7 | 2 | 6.5 | 3.6% | 0 | 0 |
| 3.0.6 | 2 | 6.5 | 3.6% | 0 | 0 |
| 3.0.5 | 2 | 6.5 | 3.6% | 0 | 0 |
| 3.0.4 | 2 | 6.5 | 3.6% | 0 | 0 |
| 3.0.3 | 2 | 6.5 | 3.6% | 0 | 0 |
| 3.0.2 | 2 | 6.5 | 3.6% | 0 | 0 |
| 3.0.1 | 3 | 6.8 | 4.1% | 0 | 0 |
| 3.0.0 | 3 | 6.8 | 4.1% | 0 | 0 |
| 2.9.9 | 2 | 7.7 | 4.5% | 0 | 0 |
| 2.9.8 | 2 | 7.7 | 4.5% | 0 | 0 |
| 2.9.7 | 2 | 7.7 | 4.5% | 0 | 0 |
| 2.9.6 | 2 | 7.7 | 4.5% | 0 | 0 |
| 2.9.5 | 2 | 7.7 | 4.5% | 0 | 0 |