{"schema_version":1,"title":"RsyncProject vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in RsyncProject: 0 in the last 7 days and 4 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-44510, was published on 20 July 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/rsyncproject","json_url":"https://junglewise.ai/threats/vendors/rsyncproject.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/rsyncproject","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":3,"all_time":10,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":4,"last_365_days":10},"latest":[{"cve":"CVE-2026-44510","cvss":6.5,"slug":"cve-2026-44510-rsync-out-of-bounds-read-in-recv-files","title":"Rsync out-of-bounds read in recv_files","severity":"medium","exploited":false,"published_at":"2026-07-20T22:17:13.957+00:00","url":"https://junglewise.ai/threats/cve-2026-44510-rsync-out-of-bounds-read-in-recv-files"},{"cve":"CVE-2026-44509","cvss":6.3,"slug":"cve-2026-44509-rsyncproject-rsync-symlink-race-in-path-based-syscalls","title":"RsyncProject rsync symlink race in path-based syscalls","severity":"medium","exploited":false,"published_at":"2026-07-20T21:16:47.243+00:00","url":"https://junglewise.ai/threats/cve-2026-44509-rsyncproject-rsync-symlink-race-in-path-based-syscalls"},{"cve":"CVE-2026-44508","cvss":8.1,"slug":"cve-2026-44508-rsync-integer-overflow-in-compressed-token-decoder","title":"Rsync integer overflow in compressed-token decoder","severity":"high","exploited":false,"published_at":"2026-07-20T21:16:47.113+00:00","url":"https://junglewise.ai/threats/cve-2026-44508-rsync-integer-overflow-in-compressed-token-decoder"},{"cve":"CVE-2026-44507","cvss":4.8,"slug":"cve-2026-44507-rsync-hostname-acl-bypass-in-chroot-daemon-mode","title":"Rsync hostname ACL bypass in chroot daemon mode","severity":"medium","exploited":false,"published_at":"2026-07-20T21:16:46.973+00:00","url":"https://junglewise.ai/threats/cve-2026-44507-rsync-hostname-acl-bypass-in-chroot-daemon-mode"},{"cve":"CVE-2026-29518","cvss":7,"slug":"cve-2026-29518-rsync-toctou-race-condition-in-daemon-file-handling","title":"Rsync TOCTOU race condition in daemon file handling","severity":"high","exploited":false,"published_at":"2026-05-20T13:16:17.04+00:00","url":"https://junglewise.ai/threats/cve-2026-29518-rsync-toctou-race-condition-in-daemon-file-handling"},{"cve":"CVE-2026-45232","cvss":3.1,"slug":"cve-2026-45232-rsync-off-by-one-stack-write-in-establish-proxy-connection","title":"Rsync off-by-one stack write in establish_proxy_connection","severity":"low","exploited":false,"published_at":"2026-05-20T02:16:36.887+00:00","url":"https://junglewise.ai/threats/cve-2026-45232-rsync-off-by-one-stack-write-in-establish-proxy-connection"},{"cve":"CVE-2026-43620","cvss":6.5,"slug":"cve-2026-43620-rsync-out-of-bounds-array-read-in-recv-files","title":"Rsync out-of-bounds array read in recv_files","severity":"medium","exploited":false,"published_at":"2026-05-20T02:16:36.727+00:00","url":"https://junglewise.ai/threats/cve-2026-43620-rsync-out-of-bounds-array-read-in-recv-files"},{"cve":"CVE-2026-43619","cvss":6.3,"slug":"cve-2026-43619-rsync-symlink-race-condition-in-path-based-system-calls","title":"Rsync symlink race condition in path-based system calls","severity":"medium","exploited":false,"published_at":"2026-05-20T02:16:36.577+00:00","url":"https://junglewise.ai/threats/cve-2026-43619-rsync-symlink-race-condition-in-path-based-system-calls"},{"cve":"CVE-2026-43618","cvss":8.1,"slug":"cve-2026-43618-rsync-integer-overflow-in-compressed-token-decoder","title":"Rsync integer overflow in compressed-token decoder","severity":"high","exploited":false,"published_at":"2026-05-20T02:16:36.41+00:00","url":"https://junglewise.ai/threats/cve-2026-43618-rsync-integer-overflow-in-compressed-token-decoder"},{"cve":"CVE-2026-43617","cvss":4.8,"slug":"cve-2026-43617-rsync-authorization-bypass-in-hostname-based-acls","title":"Rsync authorization bypass in hostname-based ACLs","severity":"medium","exploited":false,"published_at":"2026-05-20T02:16:36.233+00:00","url":"https://junglewise.ai/threats/cve-2026-43617-rsync-authorization-bypass-in-hostname-based-acls"}],"vendor":{"hub":true,"name":"RsyncProject","slug":"rsyncproject","homepage":"https://rsync.samba.org/","description":"RsyncProject is the development group responsible for the maintenance of the rsync file synchronization utility.","url":"https://junglewise.ai/threats/vendors/rsyncproject"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-44508","cvss":8.1,"slug":"cve-2026-44508-rsync-integer-overflow-in-compressed-token-decoder","title":"Rsync integer overflow in compressed-token decoder","severity":"high","exploited":false,"published_at":"2026-07-20T21:16:47.113+00:00","url":"https://junglewise.ai/threats/cve-2026-44508-rsync-integer-overflow-in-compressed-token-decoder"},{"cve":"CVE-2026-43618","cvss":8.1,"slug":"cve-2026-43618-rsync-integer-overflow-in-compressed-token-decoder","title":"Rsync integer overflow in compressed-token decoder","severity":"high","exploited":false,"published_at":"2026-05-20T02:16:36.41+00:00","url":"https://junglewise.ai/threats/cve-2026-43618-rsync-integer-overflow-in-compressed-token-decoder"},{"cve":"CVE-2026-29518","cvss":7,"slug":"cve-2026-29518-rsync-toctou-race-condition-in-daemon-file-handling","title":"Rsync TOCTOU race condition in daemon file handling","severity":"high","exploited":false,"published_at":"2026-05-20T13:16:17.04+00:00","url":"https://junglewise.ai/threats/cve-2026-29518-rsync-toctou-race-condition-in-daemon-file-handling"},{"cve":"CVE-2026-44510","cvss":6.5,"slug":"cve-2026-44510-rsync-out-of-bounds-read-in-recv-files","title":"Rsync out-of-bounds read in recv_files","severity":"medium","exploited":false,"published_at":"2026-07-20T22:17:13.957+00:00","url":"https://junglewise.ai/threats/cve-2026-44510-rsync-out-of-bounds-read-in-recv-files"},{"cve":"CVE-2026-43620","cvss":6.5,"slug":"cve-2026-43620-rsync-out-of-bounds-array-read-in-recv-files","title":"Rsync out-of-bounds array read in recv_files","severity":"medium","exploited":false,"published_at":"2026-05-20T02:16:36.727+00:00","url":"https://junglewise.ai/threats/cve-2026-43620-rsync-out-of-bounds-array-read-in-recv-files"},{"cve":"CVE-2026-44509","cvss":6.3,"slug":"cve-2026-44509-rsyncproject-rsync-symlink-race-in-path-based-syscalls","title":"RsyncProject rsync symlink race in path-based syscalls","severity":"medium","exploited":false,"published_at":"2026-07-20T21:16:47.243+00:00","url":"https://junglewise.ai/threats/cve-2026-44509-rsyncproject-rsync-symlink-race-in-path-based-syscalls"},{"cve":"CVE-2026-43619","cvss":6.3,"slug":"cve-2026-43619-rsync-symlink-race-condition-in-path-based-system-calls","title":"Rsync symlink race condition in path-based system calls","severity":"medium","exploited":false,"published_at":"2026-05-20T02:16:36.577+00:00","url":"https://junglewise.ai/threats/cve-2026-43619-rsync-symlink-race-condition-in-path-based-system-calls"},{"cve":"CVE-2026-44507","cvss":4.8,"slug":"cve-2026-44507-rsync-hostname-acl-bypass-in-chroot-daemon-mode","title":"Rsync hostname ACL bypass in chroot daemon mode","severity":"medium","exploited":false,"published_at":"2026-07-20T21:16:46.973+00:00","url":"https://junglewise.ai/threats/cve-2026-44507-rsync-hostname-acl-bypass-in-chroot-daemon-mode"},{"cve":"CVE-2026-43617","cvss":4.8,"slug":"cve-2026-43617-rsync-authorization-bypass-in-hostname-based-acls","title":"Rsync authorization bypass in hostname-based ACLs","severity":"medium","exploited":false,"published_at":"2026-05-20T02:16:36.233+00:00","url":"https://junglewise.ai/threats/cve-2026-43617-rsync-authorization-bypass-in-hostname-based-acls"},{"cve":"CVE-2026-45232","cvss":3.1,"slug":"cve-2026-45232-rsync-off-by-one-stack-write-in-establish-proxy-connection","title":"Rsync off-by-one stack write in establish_proxy_connection","severity":"low","exploited":false,"published_at":"2026-05-20T02:16:36.887+00:00","url":"https://junglewise.ai/threats/cve-2026-45232-rsync-off-by-one-stack-write-in-establish-proxy-connection"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"RsyncProject Rsync","slug":"rsync","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/rsync"}]}