Direct Vulnerabilities

Known vulnerabilities in the rsync package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Use of Uninitialized Resource

<3.5.0+ds1-1
  • H
Out-of-bounds Write

<3.5.0+ds1-1
  • M
CRLF Injection

<3.5.0+ds1-1
  • H
Algorithmic Complexity

<3.5.0+ds1-1
  • M
Improper Validation of Array Index

<3.5.0+ds1-1
  • M
Link Following

<3.5.0+ds1-1
  • M
Incorrect Authorization

<3.5.0+ds1-1
  • H
Link Following

<3.5.0+ds1-1
  • H
Allocation of Resources Without Limits or Throttling

<3.5.0+ds1-1
  • H
Out-of-bounds Write

<3.5.0+ds1-1
  • M
Incorrect Type Conversion or Cast

<3.5.0+ds1-1
  • M
Link Following

<3.5.0+ds1-1
  • H
Link Following

<3.5.0+ds1-1
  • M
Improper Validation of Specified Quantity in Input

<3.5.0+ds1-1
  • H
OS Command Injection

<3.5.0+ds1-1
  • H
Link Following

<3.5.0+ds1-1
  • H
Link Following

<3.5.0+ds1-1
  • H
Incorrect Authorization

<3.5.0+ds1-1
  • H
Out-of-bounds Write

<3.5.0+ds1-1
  • H
Not Failing Securely ('Failing Open')

<3.5.0+ds1-1
  • M
Link Following

<3.5.0+ds1-1
  • M
Link Following

<3.5.0+ds1-1
  • M
Integer Overflow or Wraparound

<3.5.0+ds1-1
  • H
Link Following

<3.5.0+ds1-1
  • C
Authentication Bypass

<3.5.0+ds1-1
  • M
Link Following

<3.5.0+ds1-1
  • H
Directory Traversal

<3.5.0+ds1-1
  • H
Allocation of Resources Without Limits or Throttling

<3.5.0+ds1-1
  • H
Reliance on Untrusted Inputs in a Security Decision

<3.5.0+ds1-1
  • H
Improper Certificate Validation

<3.5.0+ds1-1
  • H
Incorrect Calculation of Buffer Size

<3.5.0+ds1-1
  • H
Symlink Following

<3.5.0+ds1-1
  • H
Link Following

<3.5.0+ds1-1
  • M
Link Following

<3.4.3+ds1-1
  • H
Time-of-check Time-of-use (TOCTOU)

<3.4.3+ds1-1
  • L
Off-by-one Error

<3.4.3+ds1-1
  • H
Out-of-bounds Read

<3.4.3+ds1-1
  • M
Authentication Bypass

<3.4.3+ds1-1
  • M
Out-of-bounds Read

<3.4.3+ds1-1
  • L
Improper Handling of Length Parameter Inconsistency

<3.4.2+ds1-1
  • L
CVE-2025-10158

<3.4.1+ds1-7
  • H
Use of Uninitialized Resource

<3.3.0+ds1-3
  • H
Directory Traversal

<3.3.0+ds1-3
  • M
Race Condition

<3.3.0+ds1-3
  • M
Detection of Error Condition Without Action

<3.3.0+ds1-3
  • C
Out-of-bounds Write

<3.3.0+ds1-3
  • H
Directory Traversal

<3.3.0+ds1-3
  • H
Improper Input Validation

<3.2.5-1
  • H
Improper Validation of Certificate with Host Mismatch

<3.2.3-3
  • H
CVE-2018-5764

<3.1.2-2.2
  • L
Missing Authorization

<3.1.2-2.1
  • C
CVE-2017-17434

<3.1.2-2.1
  • C
Out-of-bounds Read

<3.1.2-2.1
  • C
Numeric Errors

<3.1.3-6
  • H
Numeric Errors

<3.1.3-6
  • C
Numeric Errors

<3.1.3-6
  • H
Numeric Errors

<3.1.3-6
  • L
Link Following

<3.1.1-3
  • H
Improper Input Validation

<3.1.0-3
  • L
Out-of-Bounds

<3.0.8
  • H
Out-of-Bounds

<3.0.2-1
  • L
Configuration

<2.6.9-6
  • L
Access Restriction Bypass

<2.6.9-6
  • M
CVE-2007-4091

<2.6.9-5
  • H
CVE-2006-2083

<2.6.8-1
  • M
CVE-2004-0792

<2.6.2-3
  • M
CVE-2004-0426

<2.6.1-1
  • M
CVE-2004-2093

<2.6.1-1
  • H
CVE-2003-0962

<2.5.6-1.1