VYPR

Rustdesk Server

by Rustdesk

CVEs (9)

  • CVE-2026-76840CriAug 24, 2026
    risk 0.55cvss 9.6epss 0.00

    RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in…

  • CVE-2026-57850HigJul 10, 2026
    risk 0.54cvss 8.3epss 0.01

    RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An…

  • CVE-2026-30796HigMar 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks. The client…

  • CVE-2026-3598HigMar 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Config string generation, web console export modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated…

  • CVE-2026-73108HigAug 26, 2026
    risk 0.42cvss 7.5epss 0.01

    RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted…

  • CVE-2026-73102MedAug 26, 2026
    risk 0.30cvss 5.7epss 0.00

    RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without requiring normalized relative paths. A…

  • CVE-2026-100388MedSep 25, 2026
    risk 0.28cvss 5.4epss 0.00

    RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions can place files onto the host clipboard…

  • CVE-2026-100417LowSep 25, 2026
    risk 0.13cvss 3.1epss 0.00

    RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied…

  • CVE-2026-58056HigJun 28, 2026
    risk 0.00cvss 7.6epss 0.00

    RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach…