Rsync 3.5.0 fixes 33 flaws after security audit, one critical

Rsync 3.5.0 fixes 33 flaws after security audit, one critical

The open-source file synchronization utility Rsync 3.5.0 was released on August 13, 2026. The project is written in C and distributed under the GNU General Public License. The previous stable release, Rsync 3.4.0, arrived in January 2025.

The new version fixes previously discovered bugs and addresses numerous vulnerabilities: 17 rated high severity, 15 rated medium, and one critical flaw tracked as CVE-2026-53791. When the proxy protocol parameter is set to true, a client connecting directly rather than through a trusted proxy can send a PROXY header to spoof its source address and bypass host-level access control. Exploiting some of the vulnerabilities on a server allows an attacker to target connecting clients and achieve arbitrary file read or write on their systems, limited only by the permissions of the rsync process.

The Rsync team describes the update as an "extraordinary release" due to the sheer volume of security issues: all 33 problems stemmed from a targeted audit of the path handling and daemon protocol components, along with related code.

Additional security fixes in Rsync 3.5 include closing issues with arbitrary file read and creation during transfers via symlinks on operator-supplied input files, as well as patches against arbitrary file write and privilege escalation through symlinks on operator-supplied output paths. The new release also incorporates further security hardening measures beyond the audited areas.

The scale of the remediation effort highlights how a focused review can uncover latent problems in widely deployed infrastructure software. Rsync remains a critical tool for backups and mirroring across Unix-like systems, and administrators are encouraged to upgrade promptly to the new version to mitigate the risks posed by the disclosed vulnerabilities. The release marks one of the most substantial security updates in the project's history, reflecting the growing scrutiny of foundational open-source utilities.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate