CVE-2026-70453: rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()
rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hashsearch() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70453?
The severity of CVE-2026-70453 is rated as high with a CVSS score of 7.5.
How do I fix CVE-2026-70453?
To mitigate CVE-2026-70453, upgrade to rsync version 3.5.0 or later.
What type of vulnerability is CVE-2026-70453?
CVE-2026-70453 is an algorithmic complexity vulnerability that can lead to Denial of Service.
What is the impact of exploiting CVE-2026-70453?
Exploitation of CVE-2026-70453 can result in a denial of service by exhausting the receiving system's resources.
Which software is affected by CVE-2026-70453?
CVE-2026-70453 affects all versions of the rsync tool prior to version 3.5.0.