High severity8.0NVD Advisory· Published Aug 13, 2026· Updated Aug 13, 2026
CVE-2026-70454
CVE-2026-70454
Description
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.