Impact
The vulnerability in rclone’s local backend occurs when the --links or links=true option is used; symlink targets are exposed as .rclonelink objects and an unchecked Range start value can be provided through the Range header. When that start value exceeds the length of the symlink target string, the code slices the target as linkdst[offset:], triggering a slice-bounds panic. The panic is confined to the HTTP or WebDAV request handler because Go’s net/http recovers the panic on a per-connection basis, resulting in a deterministic request‑level denial of service while the overall rclone process continues to run.
Affected Systems
rclone version 1.75.0 and earlier that have the local backend enabled with --links or links=true are affected. The flaw only manifests when the local backend is exposed via HTTP or WebDAV, so users who serve local files over those protocols are at risk.
Risk and Exploitability
With a CVSS score of 5.3 the issue is considered moderate in severity. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The likely attack vector is a remote attacker sending a crafted Range request to an HTTP or WebDAV endpoint served by the vulnerable rclone instance, provoking the panic and causing the affected request to fail.
OpenCVE Enrichment
Github GHSA