CVE-2026-79777: Rclone

Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

Affected products

  • Rclone Rclone: before 1.75.0 (fixed in 1.75.0)

Published 2026-08-25. Last modified 2026-09-10.