Files
rclone/docs/content
Nick Craig-Wood 2c1174af0d docs: add assigned CVE numbers to the v1.75.0 security advisories in the changelog
Five of the advisories released with v1.75.0 now have CVEs assigned:

- GHSA-45pq-889g-fcgh serve restic path traversal: CVE-2026-71309
- GHSA-xhf4-832v-7xcr lib/proxy CONNECT header OOM: CVE-2026-71310
- GHSA-8c48-q9wj-3w37 ftp command injection: CVE-2026-71311
- GHSA-2m8m-jhrm-w6j2 sftp PowerShell command injection: CVE-2026-71312
- GHSA-7p4m-qxvv-g567 local file name escape: CVE-2026-71313

GHSA-6jcg-q3wp-x2f4 (squashfs) loses its CVE-PENDING marker as GitHub
declined to issue a CVE from the rclone repository - the vulnerable code
is in go-diskfs so any CVE must come from an advisory there.

GHSA-mfvx-7rcj-9m5g (pprof) keeps its CVE-PENDING marker as the CVE
request is still awaiting allocation.
2026-08-18 12:29:35 +01:00
..
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-08-18 12:29:35 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-04-02 16:32:54 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-01-23 16:55:52 +00:00
2026-05-01 15:56:56 +01:00
2026-05-01 15:56:56 +01:00
2026-07-31 16:56:33 +01:00
2026-04-02 16:32:54 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-04-02 16:32:54 +01:00
2026-08-12 10:59:44 +01:00
2026-05-01 15:56:56 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-04-21 21:06:49 +02:00
2026-05-01 15:56:56 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-04-02 16:32:54 +01:00
2026-04-02 16:32:54 +01:00
2026-08-07 16:28:43 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00
2026-07-31 16:56:33 +01:00