Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client. | |
| Title | rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T15:37:23.820Z
Reserved: 2026-08-04T14:52:23.814Z
Link: CVE-2026-70454
Updated: 2026-08-13T15:37:17.720Z
Status : Received
Published: 2026-08-13T15:19:59.047
Modified: 2026-08-13T16:19:01.373
Link: CVE-2026-70454
No data.
OpenCVE Enrichment
No data.