What is CVE-2026-53789?
CVE-2026-53789 is an improper path handling vulnerability in rsync before version 3.5.0. It allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that reclassifies implied parent directory entries. Users should upgrade to rsync version 3.5.0 or later to mitigate this issue.
Azərbaycanca: CVE-2026-53789, rsync 3.5.0-dən əvvəlki versiyalarda "improper path handling" zəifliyidir. Bu, uzaqdan fayl göndərən şəxsin xüsusi hazırlanmış fayl siyahısı vasitəsilə --delete əməliyyatlarının həcmini təyinat qovluğundan kənara çıxarmasına imkan verir. İstifadəçilər rsync-i 3.5.0 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of rsync are affected by CVE-2026-53789?
This vulnerability affects all versions of rsync prior to version 3.5.0.
How can I protect against CVE-2026-53789?
You should upgrade rsync to version 3.5.0 or later to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.