Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/rclone/rclone
  4. ›
  5. GHSA-h4mf-4v27-hggj

GHSA-h4mf-4v27-hggj: rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

August 5, 2026

WebDAV’s default redirect handling can replay Basic authorization and configured Cookie headers over plaintext HTTP after a same-host HTTPS-to-HTTP redirect. This was reproduced through the real backend. Unlike the low-impact STS token in rclone’s published S3 redirect advisory, Basic passwords and session cookies are complete reusable credentials, supporting a High rating when they grant normal WebDAV read/write access.

The credible threat requires a legitimate endpoint, gateway, or accelerator to emit an unsafe redirect and an adjacent/on-path actor to observe the plaintext hop. A report should not rely on a malicious original WebDAV endpoint because that endpoint already receives the credentials.

References

  • github.com/advisories/GHSA-h4mf-4v27-hggj
  • github.com/rclone/rclone/commit/59b513b0e74fd2943ccbb8891d5ce00f860e6d26
  • github.com/rclone/rclone/releases/tag/v1.75.0
  • github.com/rclone/rclone/security/advisories/GHSA-h4mf-4v27-hggj

Code Behaviors & Features

Detect and mitigate GHSA-h4mf-4v27-hggj with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.75.0

Fixed versions

  • 1.75.0

Solution

Upgrade to version 1.75.0 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-319: Cleartext Transmission of Sensitive Information
  • CWE-522: Insufficiently Protected Credentials

Source file

go/github.com/rclone/rclone/GHSA-h4mf-4v27-hggj.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 19 Aug 2026 12:27:52 +0000.