What is CVE-2026-71310?
CVE-2026-71310 is a vulnerability in rclone's lib/proxy/http.go module where HTTP CONNECT responses are parsed with http.ReadResponse over an unrestricted buffered reader. This allows a malicious or compromised proxy server to attack the rclone client via crafted responses. Affects versions prior to 1.75.0; immediate update is recommended.
Azərbaycanca: CVE-2026-71310 rclone-in lib/proxy/http.go modulunda HTTP CONNECT cavablarının məhdudiyyətsiz buferlənmiş oxuyucu ilə işlənməsi zəifliyidir. Bu, zərərli və ya kompromat olunmuş proxy serverə rclone müştərisinə qarşı cavab vasitəsilə hücum etməyə imkan verir. 1.75.0 versiyasına qədər təsir edir, dərhal yeniləmək tövsiyə olunur.
FAQ2
In which module of rclone was the CVE-2026-71310 vulnerability discovered?
This vulnerability was discovered in the lib/proxy/http.go module of rclone.
Which version is recommended to update to in order to mitigate CVE-2026-71310?
Since it affects versions prior to 1.75.0, an immediate update to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.