What is CVE-2026-71311?
CVE-2026-71311 is a vulnerability in rclone, specifically in backend/ftp/ftp.go, where a non-default FTP filename encoding can restore raw CR/LF characters before interpolating an attacker-controlled path into the line-oriented protocol. Users are advised to update to version 1.75.0 or later.
Azərbaycanca: CVE-2026-71311 zəifliyi rclone proqramında, xüsusilə backend/ftp/ftp.go faylında aşkarlanıb. Bu, FTP backend-də qeyri-standart fayl adı kodlaması zamanı CR/LF simvollarının bərpası yolu ilə hücumçunun idarə etdiyi yolu line-oriented protokola interpolyasiya etməsinə imkan verir. İstifadəçilərə 1.75.0 versiyasına qədər yeniləmə tövsiyə olunur.
FAQ2
How can I protect against CVE-2026-71311?
Users are advised to update rclone to version 1.75.0 or later.
Which component of rclone is affected by CVE-2026-71311?
This vulnerability is located in rclone's backend/ftp/ftp.go file, specifically in the FTP backend.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.