CVE-2026-70454: Rsyncproject Rsync
High severity, CVSS 8.0. EPSS: 0.2% chance of exploitation in the next 30 days.
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.
Affected products
- Rsyncproject Rsync: up to and including 3.4.4
Published 2026-08-13. Last modified 2026-09-08.