boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-88013

rclone: http backend forwards custom/auth headers to a different host on redirect
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0019    7.5     —
AFFECTED
  Product  Versions               Fixed
  rclone   >= 1.49.0, < 1.75.1 –  —
TIMELINE
  Sep 9   Reserved by GitHub_M
  Sep 10  Published (CNA: GitHub_M)
  Sep 23  RESCORED — CVE-2026-88013 (rclone). CVSS 3.7 → 5.3 (NVD).
CWE-200, CWE-319, CWE-522 · CNA: GitHub_M · CVSS v3.1 · 5 references · NVD status: Analyzed

Description

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backend/http/http.go, while its fshttp.NewClient client follows redirects without a backend-specific http.Client.CheckRedirect policy. A configured remote that redirects to another host can therefore cause custom secrets such as X-Api-Key to be resent to that untrusted destination, and a same-host HTTPS-to-HTTP redirect can expose Authorization or Cookie headers in cleartext. Listing, stat, download, mount, and serve operations can trigger the leak during normal use. This issue is fixed in version 1.75.1.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 9, 2026ReservedReserved by GitHub_M
September 10, 2026PublishedPublished (CNA: GitHub_M)
September 23, 2026RESCOREDRESCORED — CVE-2026-88013 (rclone). CVSS 3.7 → 5.3 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
rclonerclone—>= 1.49.0, < 1.75.1—

Weaknesses

CWE-200 · CWE-319 · CWE-522

References (5)

Related

Authoritative record: CVE-2026-88013 at cve.org

Vendors: rclone

Weaknesses: CWE-200 · CWE-319 · CWE-522

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-88013 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.