CVE-2025-10158: Rsync

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.

Affected products

  • Rsync Rsync: up to and including 3.4.1

Published 2025-11-18. Last modified 2026-06-17.