Direct Vulnerabilities

Known vulnerabilities in the rsync package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • H
Algorithmic Complexity

*
  • M
Use of Uninitialized Resource

*
  • M
Link Following

*
  • H
Symlink Following

*
  • M
Incorrect Authorization

*
  • M
Link Following

*
  • H
Link Following

*
  • H
Link Following

*
  • H
Link Following

*
  • H
Link Following

*
  • H
Incorrect Authorization

*
  • H
Directory Traversal

*
  • M
Link Following

*
  • M
Improper Validation of Specified Quantity in Input

*
  • M
Incorrect Type Conversion or Cast

*
  • H
Link Following

*
  • M
Link Following

*
  • H
Out-of-bounds Write

*
  • H
Improper Certificate Validation

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Link Following

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • C
Authentication Bypass

*
  • M
CRLF Injection

*
  • H
Not Failing Securely ('Failing Open')

*
  • H
Reliance on Untrusted Inputs in a Security Decision

*
  • H
Out-of-bounds Write

*
  • H
Incorrect Calculation of Buffer Size

*
  • M
Link Following

*
  • M
Improper Validation of Array Index

*
  • H
OS Command Injection

*
  • M
Link Following

<3.4.1+ds1-5+deb13u3
  • M
Out-of-bounds Read

<3.4.1+ds1-5+deb13u3
  • H
Time-of-check Time-of-use (TOCTOU)

<3.4.1+ds1-5+deb13u3
  • L
Off-by-one Error

<3.4.1+ds1-5+deb13u4
  • M
Authentication Bypass

<3.4.1+ds1-5+deb13u3
  • H
Out-of-bounds Read

<3.4.1+ds1-5+deb13u3
  • H
Improper Handling of Length Parameter Inconsistency

<3.4.1+ds1-5+deb13u2
  • L
CVE-2025-10158

<3.4.1+ds1-5+deb13u1
  • H
Directory Traversal

<3.3.0+ds1-3
  • M
Race Condition

<3.3.0+ds1-3
  • H
Use of Uninitialized Resource

<3.3.0+ds1-3
  • C
Out-of-bounds Write

<3.3.0+ds1-3
  • M
Detection of Error Condition Without Action

<3.3.0+ds1-3
  • H
Directory Traversal

<3.3.0+ds1-3
  • H
Improper Input Validation

<3.2.5-1
  • H
Improper Validation of Certificate with Host Mismatch

<3.2.3-3
  • H
CVE-2018-5764

<3.1.2-2.2
  • L
Missing Authorization

<3.1.2-2.1
  • C
CVE-2017-17434

<3.1.2-2.1
  • C
Out-of-bounds Read

<3.1.2-2.1
  • H
Numeric Errors

<3.1.3-6
  • C
Numeric Errors

<3.1.3-6
  • C
Numeric Errors

<3.1.3-6
  • H
Numeric Errors

<3.1.3-6
  • L
Link Following

<3.1.1-3
  • H
Improper Input Validation

<3.1.0-3
  • L
Out-of-Bounds

<3.0.8
  • H
Out-of-Bounds

<3.0.2-1
  • L
Access Restriction Bypass

<2.6.9-6
  • L
Configuration

<2.6.9-6
  • M
CVE-2007-4091

<2.6.9-5
  • H
CVE-2006-2083

<2.6.8-1
  • M
CVE-2004-0792

<2.6.2-3
  • M
CVE-2004-0426

<2.6.1-1
  • M
CVE-2004-2093

<2.6.1-1
  • H
CVE-2003-0962

<2.5.6-1.1