High severity7.5NVD Advisory· Published Aug 13, 2026· Updated Aug 31, 2026
CVE-2026-70455
CVE-2026-70455
Description
rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.
Affected products
5- osv-coords4 versionspkg:rpm/opensuse/rsync&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/rsyncpkg:rpm/almalinux/rsync-rrsyncpkg:rpm/almalinux/rsync-daemon
< 3.4.1-160000.6.1+ 3 more
- (no CPE)range: < 3.4.1-160000.6.1
- (no CPE)range: < 3.5.0-3.el10_2
- (no CPE)range: < 3.5.0-3.el10_2
- (no CPE)range: < 3.5.0-3.el10_2
Patches
Vulnerability mechanics
References
3- github.com/RsyncProject/rsync/security/advisories/GHSA-rjvj-qgqg-cvx9nvdVendor Advisory
- www.vulncheck.com/advisories/rsync-dos-via-zt-zstandard-compression-thread-exhaustionnvdRelease NotesThird Party Advisory
- github.com/RsyncProject/rsync/releases/tag/v3.5.0nvdProductRelease Notes
News mentions
1- Rsync: 25 Vulnerabilities Disclosed Together, Affecting Versions Before 3.5.0Vypr Intelligence · Aug 13, 2026