Skip to content

GHSA-h2q9-5fr8-w635 on CTRL-OS 26.05

Aliases: GHSA-h2q9-5fr8-w635, CVE-2026-53791

Packages: rsync

Status: Plausible

Advisory Information

With proxy protocol = true, a client connecting directly (not via the trusted proxy) could send a PROXY header to forge its source address and bypass host-based access control (hosts allow/deny).

Fix: require the direct peer to match a configured trusted-proxy list before honouring a forwarded address.

Test: proxy-protocol-trusted-peer.

Affected: rsync 3.4.3 and earlier; fixed in 3.5.0. (Precise introduced-in ranges being finalised.)

Updates

2026-08-14 16:57 CEST

Metadata changes:

  • Status for package rsync: “Plausible

2026-08-14 16:55 CEST

Metadata changes:

  • Status for package rsync: “New