HIGHVulnerability

CVE-2026-70456

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.

Properties

severity
HIGH
score
8.2
epss_score
0.00396
cve_id
CVE-2026-70456
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
published_at
2026-08-13T15:19:59.343
last_modified
2026-09-08T20:28:37.587
epss_percentile
0.32851

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Write

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-70456 — Ninja Signal Threat Intelligence | Ninja Signal