CVE-2026-70453

ADVISORY - nist

Summary

rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.

EPSS Score: 0.00525 (0.425)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Inefficient Algorithmic Complexity


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in