Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95834.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-95834
Upstream
Published
2026-08-13T15:19:43Z
Modified
2026-09-20T05:33:47Z
Summary
CVE-2026-53790 affecting package rsync for versions less than 3.5.0-1
Details

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.

References

Affected packages

Azure Linux:3 / rsync

Package

Name
rsync
Purl
pkg:rpm/azure-linux/rsync

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.5.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95834.json"