<Vulnerability name="CVE-2026-79780">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-25T15:16:09</PublicDate>
    <Bugzilla id="2523578" url="https://bugzilla.redhat.com/show_bug.cgi?id=2523578" xml:lang="en:us">
github.com/rclone/rclone: rclone: Information disclosure via S3 redirect callbacks
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-201</CWE>
    <Details xml:lang="en:us" source="Mitre">
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted endpoint can capture reusable IBM IAM tokens on same-host HTTPS-to-HTTP downgrades or SSE-C keys on cross-origin redirects to access protected S3 objects.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in rclone. The application fails to properly sanitize IBM IAM bearer tokens and Server-Side Encryption with Customer-Provided Keys (SSE-C) encryption keys during S3 redirect callbacks. This allows credentials to be preserved across scheme or host changes. A remote attacker observing network traffic from a trusted endpoint could capture reusable IBM IAM tokens on same-host HTTPS-to-HTTP downgrades or SSE-C keys on cross-origin redirects, leading to information disclosure and potential unauthorized access to protected S3 objects.
    </Details>
    <Statement xml:lang="en:us">
This Moderate flaw in rclone allows for information disclosure of IBM IAM bearer tokens or SSE-C encryption keys. When rclone interacts with S3 endpoints that issue unsafe redirects, an adjacent network attacker can capture these credentials during HTTPS-to-HTTP downgrades or cross-origin redirects. The impact is constrained by the scope of the captured token and the attacker's access to encrypted objects.
    </Statement>
    <Mitigation xml:lang="en:us">
Until packages are updated, avoid using rclone S3 remotes with IBM IAM bearer tokens or SSE-C customer-provided keys against endpoints or gateways that issue cross-scheme or cross-host redirects. Prefer trusted HTTPS endpoints that do not downgrade or redirect secret-bearing requests.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:cryostat:4">
        <ProductName>Cryostat 4</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>cryostat/cryostat-storage-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhacm2/volsync-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-79780
https://nvd.nist.gov/vuln/detail/CVE-2026-79780
https://github.com/rclone/rclone/security/advisories/GHSA-8mxv-9xhp-86h4
https://www.vulncheck.com/advisories/rclone-before-credential-exposure-via-s3-redirect
    </References>
</Vulnerability>