THREAT OPS › Threat News › [NVD] CVE-2026-79775 (MEDIUM 6.5) — rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and me
[NVD] CVE-2026-79775 (MEDIUM 6.5) — rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and me
CVE-2026-79775 CVSS: 6.5 MEDIUM Published: 2026-08-25T16:17:29.233
rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and metadata values before use. An attacker who can place
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-79775cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-79775