CVE-2026-88045 | rclone up to 1.75.0 Serve S3 Streamed Multipart multipart.go multipart.NewRW contentLength allocation of resources

SecurityVulns

A vulnerability classified as problematic has been found in rclone up to 1.75.0. Affected by this vulnerability is the function multipart.NewRW of the file cmd/serve/s3/multipart.go of the component Serve S3 Streamed Multipart. The manipulation of the argument contentLength leads to allocation of resources.

This vulnerability is traded as CVE-2026-88045. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More