CVE-2026-53791: rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53791?
CVE-2026-53791 has a critical severity score of 9.1.
How do I fix CVE-2026-53791?
To fix CVE-2026-53791, upgrade to rsync version 3.5.0 or later.
What type of vulnerability is CVE-2026-53791?
CVE-2026-53791 is an IP spoofing vulnerability in the rsync daemon.
Who is affected by CVE-2026-53791?
Any user running rsync daemon versions prior to 3.5.0 is potentially affected by CVE-2026-53791.
What can attackers do with CVE-2026-53791?
Attackers can bypass IP-based access controls and perform unauthorized actions by sending a crafted PROXY protocol header.