JLSEC-2026-630

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-630.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-630.json
JSON Data
https://api.test.osv.dev/v1/vulns/JLSEC-2026-630
Upstream
  • EUVD-2026-31010
  • GHSA-pwrq-5rj3-c43m
Published
2026-06-25T17:41:14.392Z
Modified
2026-06-25T17:49:20.322102323Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system...
Details

Rsync versionĀ 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

Database specific
{
    "sources": [
        {
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43619",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-43619",
            "id": "CVE-2026-43619",
            "database_specific": {
                "status": "Analyzed"
            },
            "modified": "2026-06-17T10:49:55.293Z",
            "published": "2026-05-20T02:16:36.577Z",
            "imported": "2026-06-25T17:27:23.339Z"
        },
        {
            "html_url": "https://github.com/advisories/GHSA-pwrq-5rj3-c43m",
            "imported": "2026-06-25T17:27:27.359Z",
            "id": "GHSA-pwrq-5rj3-c43m",
            "modified": "2026-05-20T03:31:41Z",
            "published": "2026-05-20T03:31:33Z",
            "url": "https://api.github.com/advisories/GHSA-pwrq-5rj3-c43m"
        },
        {
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31010",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-31010",
            "id": "EUVD-2026-31010",
            "modified": "2026-05-20T13:09:14Z",
            "published": "2026-05-20T00:49:14Z",
            "imported": "2026-06-25T17:27:24.675Z"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / rsync_jll

Package

Name
rsync_jll
Purl
pkg:julia/rsync_jll?uuid=191d6b87-264a-55f5-a0e2-c8fbce9a1ce0

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.4+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-630.json"