THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gx4c-2hqx-cw2r (low) — rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

[GHSA] GHSA-gx4c-2hqx-cw2r (low) — rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

highgithub_advisoriesPublished 2026-08-05

GHSA-gx4c-2hqx-cw2r Severity: low CVE: None

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

## Vulnerability Details

**File**: `backend/s3/s3.go` **Lines**: 1359-1380 (functions `s3CheckRedirect` / `s3RedirectCrossesHost`)

### Root Cause Commit `e7b1eb774` (released in v1.74.3) added a `CheckRedirect` policy for the S3 HTTP client whose purpose is to

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gx4c-2hqx-cw2r