Impact
rclone is a command‑line tool for syncing to cloud storage. In the 1.75.0 build, the S3 multipart streaming handler reserves memory based on an attacker‑controlled Content‑Length header before receiving any payload data. Because the reserved buffer can be up to 1 MiB pages per declared length, an attacker can repeatedly send requests with a very large Content‑Length and no body, causing the program to allocate large amounts of memory. This can exhaust process or system memory and permanently block request handlers, resulting in a denial‑of‑service condition. The weakness is identified as both CWE‑770 (Use of Excessive Memory Allocation) and CWE‑789 (Memory Allocation with Excessive Size).
Affected Systems
The vulnerability exists in rclone version 1.75.0 and is fixed in the newer 1.75.1 release. Any deployments using the unpatched 1.75.0 binary, especially those exposing the S3 serve endpoint to external clients, are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers able to reach the exposed S3 serve endpoint can craft HTTP requests with large declared lengths to trigger memory exhaustion, causing the service to become unresponsive. The attack does not require authentication for anonymous deployments and only requires a valid S3 key for authenticated deployments.
OpenCVE Enrichment
Github GHSA