What is CVE-2026-53791?
CVE-2026-53791 is an IP address spoofing vulnerability in rsync daemon versions before 3.5.0. It allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Upgrading to version 3.5.0 is strongly recommended.
Azərbaycanca: CVE-2026-53791 rsync daemon-un 3.5.0 versiyasına qədər olan versiyalarında IP-spoofing zəifliyidir. Uzaqdan autentifikasiya olunmamış hücumçulara saxta PROXY protokol başlığı göndərərək IP-əsaslı giriş idarəetməsini keçməyə imkan verir. Təsirlənən sistemlərdə dərhal 3.5.0 versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What software is affected by CVE-2026-53791?
This vulnerability affects rsync daemon versions prior to 3.5.0.
What action is recommended to mitigate CVE-2026-53791?
It is strongly recommended to immediately upgrade rsync daemon to version 3.5.0 on affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.