CVE-2026-79777
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
25/08/2026
Last modified:
28/08/2026
Description
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
2.70
Severity 3.x
LOW



