CVE-2026-79777

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
25/08/2026
Last modified:
28/08/2026

Description

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.