CVE-2026-53794
ADVISORY - nistSummary
rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service.
EPSS Score: 0.00372 (0.301)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Validation of Specified Quantity in Input
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in