Critical severity9.1NVD Advisory· Published Aug 13, 2026· Updated Aug 31, 2026
CVE-2026-53791
CVE-2026-53791
Description
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords4 versionspkg:rpm/almalinux/rsync-rrsyncpkg:rpm/almalinux/rsyncpkg:rpm/opensuse/rsync&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/rsync-daemon
< 3.2.7-1.el9_8+ 3 more
- (no CPE)range: < 3.2.7-1.el9_8
- (no CPE)range: < 3.2.7-1.el9_8
- (no CPE)range: < 3.4.1-160000.6.1
- (no CPE)range: < 3.2.7-1.el9_8
Patches
Vulnerability mechanics
References
3- github.com/RsyncProject/rsync/security/advisories/GHSA-h2q9-5fr8-w635nvdVendor Advisory
- www.vulncheck.com/advisories/rsync-daemon-ip-spoofing-via-proxy-protocol-headernvdRelease NotesThird Party Advisory
- github.com/RsyncProject/rsync/releases/tag/v3.5.0nvdProductRelease Notes
News mentions
0No linked articles in our index yet.