Description
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to multipart.NewRW().Reserve before reading request-body bytes. waitForTurn admits the current part and one oversized part when the buffer is empty despite --multipart-streaming-buffer-limit, and lib/pool allocates 1 MiB pages according to Content-Length or X-Amz-Decoded-Content-Length. A network client can retain or multiply these reservations without sending the declared body, exhausting process or host memory or permanently blocking request handlers. Anonymous S3 deployments require no credentials, while deployments using auth_key require an accepted S3 key. This issue is fixed in version 1.75.1.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Memory Exhaustion
Action: Immediate Patch
AI Analysis

Impact

rclone is a command‑line tool for syncing to cloud storage. In the 1.75.0 build, the S3 multipart streaming handler reserves memory based on an attacker‑controlled Content‑Length header before receiving any payload data. Because the reserved buffer can be up to 1 MiB pages per declared length, an attacker can repeatedly send requests with a very large Content‑Length and no body, causing the program to allocate large amounts of memory. This can exhaust process or system memory and permanently block request handlers, resulting in a denial‑of‑service condition. The weakness is identified as both CWE‑770 (Use of Excessive Memory Allocation) and CWE‑789 (Memory Allocation with Excessive Size).

Affected Systems

The vulnerability exists in rclone version 1.75.0 and is fixed in the newer 1.75.1 release. Any deployments using the unpatched 1.75.0 binary, especially those exposing the S3 serve endpoint to external clients, are vulnerable.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers able to reach the exposed S3 serve endpoint can craft HTTP requests with large declared lengths to trigger memory exhaustion, causing the service to become unresponsive. The attack does not require authentication for anonymous deployments and only requires a valid S3 key for authenticated deployments.

Generated by OpenCVE AI on September 21, 2026 at 05:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade rclone to version 1.75.1 or later.
  • Restrict access to the rclone S3 serve endpoint to trusted hosts or networks.
  • If restricting access is not feasible, consider disabling the S3 serve functionality until the patched version is deployed.

Generated by OpenCVE AI on September 21, 2026 at 05:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2p48-j3qc-rx9f rclone: S3 multipart declared-length memory exhaustion
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Important


Fri, 11 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Rclone
Rclone rclone
Vendors & Products Rclone
Rclone rclone

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to multipart.NewRW().Reserve before reading request-body bytes. waitForTurn admits the current part and one oversized part when the buffer is empty despite --multipart-streaming-buffer-limit, and lib/pool allocates 1 MiB pages according to Content-Length or X-Amz-Decoded-Content-Length. A network client can retain or multiply these reservations without sending the declared body, exhausting process or host memory or permanently blocking request handlers. Anonymous S3 deployments require no credentials, while deployments using auth_key require an accepted S3 key. This issue is fixed in version 1.75.1.
Title rclone: S3 multipart declared-length memory exhaustion
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-10T17:31:43.950Z

Reserved: 2026-09-09T21:22:45.433Z

Link: CVE-2026-88045

cve-icon Vulnrichment

Updated: 2026-09-10T17:31:35.004Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T17:17:08.530

Modified: 2026-09-10T19:54:25.810

Link: CVE-2026-88045

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T16:11:39Z

Links: CVE-2026-88045 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:30:07Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling

  • CWE-789

    Memory Allocation with Excessive Size Value