High severity7.5NVD Advisory· Published Aug 13, 2026
CVE-2026-70455
CVE-2026-70455
Description
rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.