{"id":"openSUSE-SU-2026:21999-1","summary":"Security update for rclone","details":"This update for rclone fixes the following issues:\n\nChanges in rclone:\n\n- Update to version 1.75.1: (boo#1279548)\n  - Security\n    - archive\n      - Fix zip slip path traversal in untrusted zip files\n        GHSA-66hp-wgxq-6f5q CVE-PENDING (Nick Craig-Wood)\n      - Hide any archive entry which escapes the directory being\n        listed GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n      - Reject unsafe entry names when mounting squashfs images\n        GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n      - Fix zip subdirectory root matching sibling directories\n        GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n      - Fix zip entry named \".\" hiding every other file\n        GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n      - Fix \"directory not found\" for archive paths containing \"./\"\n        or \"//\" GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n    - build\n      - Fix multiple CVEs by upgrading to go1.26.6 (Nick\n        Craig-Wood)\n        - CVE-2026-56860: net/url: quadratic complexity in\n          resolvePath\n        - CVE-2026-56858: html/template: JavaScript regexp context\n          tracking\n        - CVE-2026-56862: crypto/tls: limit handshake messages\n          accepted post-handshake\n        - CVE-2026-56853: net/http: apply ReadHeaderTimeout to\n          unencrypted HTTP/2 check\n        - CVE-2026-56859: encoding/xml: recursion depth guard\n          during decode\n        - CVE-2026-33818: encoding/asn1: enforce maximum recursion\n          depth\n        - CVE-2026-46600: net: panic parsing an invalid SVCB or\n          HTTPS RR in dnsmessage\n        - CVE-2026-39821: net/http: reject ASCII-only\n          Punycode-encoded labels in idna\n      - Update golang.org/x/crypto to v0.56.0 to fix multiple CVEs\n        (Nick Craig-Wood)\n        - CVE-2026-56854: ssh: source-address critical option not\n          enforced for non-public-key auth callbacks\n        - CVE-2026-78662: ssh: a malicious peer could flood an\n          undecided channel's incoming requests, deadlocking the\n          connection\n        - CVE-2026-56855: ssh: a malicious peer could send crafted\n          messages on an established channel, deadlocking the\n          connection\n      - Update golang.org/x/image to v0.45.0 to fix CVE-2026-46603\n        (Nick Craig-Wood)\n        - CVE-2026-46603: excessive memory allocation during VP8L\n          decoding\n      - fs: Confine directory listing entries that escape the root\n        GHSA-3vxh-3pcx-9m8q GHSA-38xv-hf3p-h7mq CVE-PENDING (Nick\n        Craig-Wood)\n      - fshttp: Don't send --header values to other hosts on\n        redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick Craig-Wood)\n      - http: Don't leak configured headers to other hosts or over\n        plaintext on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick\n        Craig-Wood)\n      - lib/rest: Check HTTPS downgrades against the original\n        request on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick\n        Craig-Wood)\n      - local\n        - Fix dir metadata escaping the root through a planted\n          symlink GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood)\n        - Fix btime escaping the root via a planted symlink\n          GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood)\n        - Fix panic on Range request past the end of a symlink\n          GHSA-p6m2-r3w9-mpxw CVE-PENDING (Nick Craig-Wood)\n      - serve docker\n        - Reject volume names that escape the base directory\n          GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)\n        - Reject volume names resolving to the base directory\n          itself GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)\n        - Re-derive volume mountpoint from name when restoring\n          state GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)\n      - serve ftp: Fix auth-proxy sessions sharing credentials by\n        username GHSA-c476-6w5q-jw77 CVE-PENDING (Nick Craig-Wood)\n      - serve s3\n        - Fix memory exhaustion from client-declared multipart part\n          size GHSA-2p48-j3qc-rx9f CVE-PENDING (Nick Craig-Wood)\n        - Reject bogus multipart part sizes in the reorder buffer\n          GHSA-2p48-j3qc-rx9f (Nick Craig-Wood)\n        - Fix auth proxy accepting any request signed with an empty\n          secret GHSA-xwwr-4h3p-r22c CVE-PENDING (Nick Craig-Wood)\n        - NB the auth proxy protocol for serve s3 has changed - the\n          proxy program is now given the access key ID as user and\n          must return the secret as _secret_access_key\n        - Fix each server accepting the --auth-key credentials of\n          all the others (Nick Craig-Wood)\n        - Fix misleading anonymous access log when using an auth\n          proxy via rc GHSA-p569-5gjg-9cmj CVE-PENDING (Nick\n          Craig-Wood)\n      - serve sftp: Fix auth proxy configured via rc being silently\n        ignored GHSA-p569-5gjg-9cmj CVE-PENDING (Nick Craig-Wood)\n  - Bug Fixes\n    - accounting\n      - Fix memory leak on long-running rcd (nielash)\n      - Fix memory leak from stats groups on long-running rcd\n        (nielash)\n      - Fix bwlimit burst overflow (Rayan Salhab)\n    - bisync\n      - Fix memory leak when running via the rc (nielash)\n      - Fix failed transfers of empty files being recorded as\n        synced (Nick Craig-Wood)\n    - build: Make go1.26 the minimum required version as needed by\n      golang.org/x/crypto v0.56.0 (Nick Craig-Wood)\n    - config: Redact env var config values in logs (Pastalikek65)\n    - doc fixes (Anton Karpov, CAOShurong, Dean Chen, Nick\n      Craig-Wood, Recoordinate, Rodrigo Rodrigues, Shantanav\n      Mukherjee, shaurya)\n    - lib/batcher: Prevent commits racing shutdown (Loi Nguyen)\n    - lib/transform: Fix panic in truncate_keep_extension (VXNCXNX)\n    - multipart: Fix chunked uploads storing truncated objects when\n      the source ends early (Nick Craig-Wood)\n    - operations: Fix silent truncation of streaming uploads whose\n      source ends early (Nick Craig-Wood)\n    - serve\n      - Fix VFS instance leaks on server startup failures and\n        shutdown (Hakan İSMAİL)\n      - Pass the client IP address to the auth proxy\n        (am-at-enrollvb)\n    - serve http: Prevent scrolling to the top on page reload (Sune\n      Mølgaard)\n    - serve nfs: Fix EIO when creating symlinks with --vfs-links\n      (SillyZir)\n    - serve s3\n      - Fix failed uploads deleting or corrupting the object at the\n        key (Nick Craig-Wood)\n      - Fix crash when a multipart upload is aborted while a part\n        is uploading (Nick Craig-Wood)\n      - Fix modtime not being set when only mtime metadata is\n        supplied on PUT (Nick Craig-Wood)\n      - Upload all multipart uploads via the VFS so they obey\n        --bwlimit and show in stats (Nick Craig-Wood)\n      - Reserve the .rclone_temp_ prefix for temporary objects\n        (Nick Craig-Wood)\n      - Clean up abandoned multipart uploads after\n        --multipart-expiry (Nick Craig-Wood)\n    - vfscache\n      - Fix reader deadlock when the item size drops below the read\n        offset (Dave)\n      - Fix log message growing without bound on repeated write\n        errors (Vijay Misal)\n    - walk: Stop directory traversal when the context is cancelled\n      (Rahman Yilmaz)\n  - VFS\n    - Synchronize poll updates with shutdown (Loi Nguyen)\n    - Make poll shutdown lifecycle deterministic (Loi Nguyen)\n  - Crypt\n    - Fix hash mismatches with no_data_encryption on backends which\n      check upload hashes (Nick Craig-Wood)\n    - Fix directory names which look like versioned file names\n      (TowyTowy)\n    - Warn about directories with legacy version-like encrypted\n      names (Nick Craig-Wood)\n  - Azure Blob\n    - Fix Entra ID server-side copy source authentication (Edward\n      Klesel)\n    - Fix spurious vfs cache corruption errors during chunked reads\n      (Nick Craig-Wood)\n  - Azurefiles\n    - Fix zero padded files being created when the source ends\n      early (Nick Craig-Wood)\n  - Box\n    - Fix truncated files being uploaded successfully when the\n      source ends early (Rohit Behera)\n  - Compress\n    - Fix corrupted objects being created when the source ends\n      early (Nick Craig-Wood)\n  - Drive\n    - Don't list trashed files when removing a directory into the\n      trash (alliasgher)\n  - Dropbox\n    - Preserve Paper export paths on lookup (Loi Nguyen)\n    - Fix context cancellation (e.g. --max-duration limit) not\n      stopping in-flight requests (debaditya)\n    - Fix chunked uploads of truncated files never finishing (Nick\n      Craig-Wood)\n    - Don't retry chunked upload requests when the upload has been\n      cancelled (Nick Craig-Wood)\n    - Decode received shared-file names (Sanjay Kanth A)\n    - Fix ChangeNotify when the root's case differs from Dropbox's\n      (Loi Nguyen)\n  - Filelu\n    - Fix truncated files being uploaded successfully when the\n      source ends early (Nick Craig-Wood)\n    - Fix duplicate root path during multipart folder creation\n      (kingston125)\n  - Huaweidrive\n    - Fix truncated files being uploaded successfully when the\n      source ends early (Rohit Behera)\n  - Iclouddrive\n    - Fix uploads into an app container failing with 412 (Christian\n      De Santis)\n  - Internetarchive\n    - Fix corrupted files being created when the source ends early\n      (Nick Craig-Wood)\n  - Internxt\n    - Persist rotated token returned by the user info call\n      (0rangeSeaW0lf)\n  - Onedrive\n    - Fix 403 Forbidden for configuration personal onedrive\n      (machsix)\n    - Fall back to manual drive ID entry when drive listing fails\n      (SillyZir)\n    - Don't retry multipart upload chunk on 404 (upload session not\n      found) (water)\n  - Overview\n    - Fix \"internal error: no overview data found\" on 32 bit\n      architectures (Nick Craig-Wood)\n  - Pikpak\n    - Fix truncated files being created when the source ends early\n      (Nick Craig-Wood)\n    - Fix truncated single part uploads reported as ok when source\n      ends early (Nick Craig-Wood)\n  - Protondrive\n    - Fix files uploaded with v1.75.0 not being readable in the\n      Proton apps (Nick Craig-Wood)\n    - Fix corrupted uploads after a retried upload error (Nick\n      Craig-Wood)\n  - Quatrix\n    - Fix chunk upload retries and fix memory leak (Nick\n      Craig-Wood)\n  - S3\n    - Update Mega endpoints (Nick Craig-Wood)\n    - Treat UploadPart success without ETag as retryable error\n      (CAOShurong)\n    - Fix server side copy failing with --s3-no-head-object\n      (Anatoly Tarnavsky)\n  - Sia\n    - Fix corrupted files being created when the source ends early\n      (Nick Craig-Wood)\n  - Smb\n    - Reuse the upload connection for SetModTime (alliasgher)\n  - WebDAV\n    - Fix SetModTime failing and hashes missing on Nextcloud (Nick\n      Craig-Wood)\n  - Yandex\n    - Fix truncated files being uploaded successfully when the\n      source ends early (Rohit Behera)\n\n- Update to version 1.75.0:\n  - New S3 Providers\n    - Scality (RING / ARTESCA)\n    - Zero Services (ZERO-Z3)\n  - Security\n    - archive: Don't crash on malformed squashfs images\n      GHSA-6jcg-q3wp-x2f4 CVE-PENDING (Nick Craig-Wood)\n    - ftp: Fix ftp command injection when encoding doesn't include\n      CRLF GHSA-8c48-q9wj-3w37 CVE-PENDING (Nick Craig-Wood)\n    - lib/http: Use TLS on all --addr listeners when --cert and\n      --key are set GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)\n    - lib/proxy: Fix unbounded HTTP CONNECT headers causing OOM\n      GHSA-xhf4-832v-7xcr CVE-PENDING (Nick Craig-Wood)\n    - local: Stop source file names escaping the destination\n      directory GHSA-7p4m-qxvv-g567 CVE-PENDING (Nick Craig-Wood)\n    - rc\n      - Don't expose pprof debug handlers on an unauthenticated\n        server GHSA-mfvx-7rcj-9m5g CVE-PENDING (Nick Craig-Wood)\n      - Require authentication to list the remotes with --rc-serve\n        GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)\n      - Fix leaking stack traces on panics GHSA-gwfq-86j8-7qhv\n        (Nick Craig-Wood)\n    - s3\n      - Fix redirect credential leaks, reject HTTPS-\u003eHTTP and strip\n        secrets GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood)\n      - Strip S3 Express session token on cross-host redirects\n        GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood)\n      - serve ftp: Use constant time comparison for password check\n        GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)\n      - serve restic: Fix path traversal above the served directory\n        GHSA-45pq-889g-fcgh CVE-PENDING (Nick Craig-Wood)\n      - serve sftp: Don't crash the whole server on a bad request\n        GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood)\n      - sftp: Fix command injection via crafted filenames on\n        PowerShell remotes GHSA-2m8m-jhrm-w6j2 CVE-PENDING (Nick\n        Craig-Wood)\n      - vfs: Don't crash the process if a backend panics on a\n        background goroutine GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood)\n    - webdav\n      - Fix HTTPS to HTTP redirects leaking credentials\n        GHSA-h4mf-4v27-hggj (Nick Craig-Wood)\n      - Tus: fix potential nil pointer crash GHSA-3x6r-wxxg-53vv\n        (Nick Craig-Wood)\n    - Update google.golang.org/grpc to fix multiple security\n      problems (Nick Craig-Wood)\n  - New Features\n    - build: Update all dependencies (Nick Craig-Wood)\n    - config\n      - Add config unset command to remove options from a remote\n        (Nick Craig-Wood)\n      - Add tier to config wizard (dougal)\n    - docker serve\n      - Add timeout to volume restore so slow remotes don't block\n        startup (Nick Craig-Wood)\n      - Restore volumes concurrently so one slow remote doesn't\n        block others (Nick Craig-Wood)\n      - Make Create idempotent to avoid \"volume already exists\"\n        after restart (Nick Craig-Wood)\n    - doc fixes (blackflytech, dougal, Giridhar, KTibow,\n      mathieulongtin, Nick Craig-Wood, p1, Socialpranker, Søren\n      Lindberg, yashanil98)\n    - filter\n      - Support nested {} alternates in glob filters (maximilize)\n      - Add --files-from0 to support NUL-delimited input (Gaurav)\n    - fserrors: Make http2 \"server sent GOAWAY\" a retriable error\n      (phatlc)\n    - fshttp\n      - Add --dump errors to dump only failed HTTP transactions\n        (Nick Craig-Wood)\n      - Add --dump trace to log connection level events via\n        httptrace (Nick Craig-Wood)\n    - gui\n      - Serve static files with gzip/deflate compression (Leon\n        Brocard)\n      - Respect explicit --rc-allow-origin instead of always\n        deriving it from the bind address (Kyue)\n      - Update embedded release to 1.1.11 (Nick Craig-Wood)\n    - mount2: Add --allow-idmap to advertise FUSE_ALLOW_IDMAP\n      (Valerij Fredriksen)\n    - nfsmount: Call mount_nfs directly on OpenBSD so -T is\n      accepted (Socialpranker)\n    - rc\n      - Respond with 202 if prefer-async header is passed (FTCHD)\n      - Add config/oauthstop and config/oauthstatus to control\n        oauth listener (FTCHD)\n      - Include OAuth authorization URL in rc config/oauthstatus\n        response (Hakan İSMAİL)\n      - Allow setting rc config and filter options as flat\n        parameters (Hakan İSMAİL)\n    - serve\n      - Support custom http response headers (kkocdko)\n      - Update serve remote control to accept nested as well as\n        flat options (Hakan İSMAİL)\n    - serve dlna: Bound SOAP request bodies (Acts1631)\n    - serve nfs\n      - Allow NFS clients to mount subpaths of the served remote\n        (Nick Craig-Wood)\n      - Advertise AUTH_UNIX so the *BSD NFS clients can mount\n        (Socialpranker)\n    - serve s3: Stream multipart uploads to the backend instead of\n      buffering in memory (Nick Craig-Wood)\n    - serve sftp\n      - Implement statvfs@openssh.com to report disk usage (Nick\n        Craig-Wood)\n      - Use the requested atime when setting file times (Nick\n        Craig-Wood)\n    - serve webdav: Add gzip compression for compressible responses\n      (Leon Brocard)\n    - serve http: Add --disable-dir-list flag (Leon Brocard)\n  - Bug Fixes\n    - archive/squashfs: Fix reading images with no fragment or\n      xattr table (maximilize)\n    - chunkedreader: Fix spurious errors when a parallel stream is\n      closed early (Nick Craig-Wood)\n    - config\n      - Fix config_template_file and config_template being ignored\n        via config/create (hexbinoct)\n      - Fix normalization when obscuring passwords (Nick\n        Craig-Wood)\n    - docker serve: Fix plugin timeout on restart when volumes have\n      active mounts (Nick Craig-Wood)\n    - fs: Fix passwords and tokens appearing in the debug log\n      during rclone config (Nick Craig-Wood)\n    - gui: Fix cross-origin API requests when bound to a wildcard\n      address (FTCHD)\n    - hash: Fix xxh128 hasher size (Yuhang Cao)\n    - log: Fix side effects when importing rclone as a library\n      (Sven Rebhan)\n    - march\n      - Fix unnecessarily listing dst directory when src listing\n        finished (Nick Craig-Wood)\n      - Fix goroutine leak on completed async rc jobs (Yash Anil)\n    - nfsmount: Fix mount_nfs options incompatible with OpenBSD\n      (Socialpranker)\n    - rc\n      - Fix operations/stat for directories with large parent dirs\n        (Nick Craig-Wood)\n      - Fix _filter and _config parameters being ignored by mount/*\n        commands (Hakan İSMAİL)\n    - serve: Fix auth proxy using stale config parameters when\n      making a backend (Nick Craig-Wood)\n    - serve s3\n      - Fix aborted multipart uploads appearing as ghosts (Nick\n        Craig-Wood)\n      - Fix streamed multipart uploads not being atomic (Nick\n        Craig-Wood)\n      - Fix OOM and InvalidPart errors with concurrent multipart\n        uploads (Nick Craig-Wood)\n    - sync: Fix --fix-case rename on backends that need upload\n      before overwrite (Nick Craig-Wood)\n    - Mount\n      - Support flat VFS and Mount options in mount RC command\n        (Hakan İSMAİL)\n    - VFS\n      - Fix IO error by recreating the cache file if it has been\n        removed (Nick Craig-Wood)\n      - Fix \"invalid seek position\" error when cache files larger\n        than the remote (Nick Craig-Wood)\n      - Fix vfs cache writeback timer not being stopped when\n        --transfers reached (Nick Craig-Wood)\n      - Fix crash when multiple mounts or servers share the same\n        VFS (Nick Craig-Wood)\n    - Local\n      - Add --local-fatal-if-no-space flag (ferrumclaudepilgrim)\n      - Don't resolve relative roots to absolute paths (Nick\n        Craig-Wood)\n    - Archive\n      - Fix squashfs listings failing with invalid argument after\n        update (Nick Craig-Wood)\n    - Azure Blob\n      - Fix MD5 being dropped on range reads causing vfs cache\n        re-downloads (Nick Craig-Wood)\n      - Add use_arrow_list flag for experimental Apache Arrow\n        listing (Nick Craig-Wood)\n      - List very large containers in parallel with\n        list_parallelism (Nick Craig-Wood)\n    - Azurefiles\n      - Fix incorrect modtime after uploading a file or setting its\n        modtime (Nick Craig-Wood)\n      - Improve modtime precision from 1s to 100ns (Nick\n        Craig-Wood)\n    - Combine\n      - Don't return an error message as the remote name for a bad\n        object (Nick Craig-Wood)\n    - Drime\n      - Remove stale mux_status field from Item (Nick Craig-Wood)\n    - Drive\n      - Warn in config wizard before using the shared client_id\n        (Nick Craig-Wood)\n      - Detect shortcut loops to avoid infinite recursion (Nick\n        Craig-Wood)\n    - Dropbox\n      - Add support for impersonate_admin (Gaurav)\n      - Add --dropbox-skip-shared-folders and\n        --dropbox-skip-unowned-folders (Gaurav)\n      - Make Rmdir use one less API call (Socialpranker)\n      - Use much less memory when uploading small files (Nick\n        Craig-Wood)\n      - Remove an unnecessary API call when uploading small files\n        (Nick Craig-Wood)\n    - Filen\n      - Fix incorrect modtime after updating a file or setting its\n        modtime (Nick Craig-Wood)\n    - Filescom\n      - Fix missing MD5 hash after uploading a file (Nick\n        Craig-Wood)\n    - FTP\n      - Fix incorrect modtime after uploading a file or setting its\n        modtime (Nick Craig-Wood)\n    - Googlephotos\n      - Warn in config wizard before using the shared client_id\n        (Nick Craig-Wood)\n    - Hasher\n      - Fix Update not storing hashes in bolt DB after file\n        replacement (Nick Craig-Wood)\n    - Hdfs\n      - Fix incorrect modtime after uploading a file or setting its\n        modtime (Nick Craig-Wood)\n    - Hidrive\n      - Fix incorrect modtime after setting a file's modtime (Nick\n        Craig-Wood)\n    - HTTP\n      - Don't list parent directory when pointing at a single file\n        (Nick Craig-Wood)\n      - Add Prefer to CORS Access-Control-Allow-Headers header\n        (sijie-Z)\n    - Iclouddrive\n      - Fix \"cannot unmarshal number\" error when listing photo\n        albums (Nick Craig-Wood)\n      - Fix 2FA failing with 409 even when the code is valid (Punya\n        Jain)\n    - Imagekit\n      - Fix Open with a RangeOption returning the wrong data (Nick\n        Craig-Wood)\n      - Add mtime to the available metadata (Nick Craig-Wood)\n    - Internxt\n      - Add Move and DirMove methods for server-side file and\n        directory operations (jzunigax2)\n      - Handle file size limit errors during uploads (jzunigax2)\n      - Surface re-login error when re-auth fails in NewFs\n        (0rangeSeaW0lf)\n    - Jottacloud\n      - Fix incorrect modtime after setting a file's modtime (Nick\n        Craig-Wood)\n    - Linkbox\n      - Retry bot protection HTML challenge responses instead of\n        failing (Nick Craig-Wood)\n    - Mailru\n      - Fix incorrect modtime after updating a file or setting its\n        modtime (Nick Craig-Wood)\n    - Mega\n      - Fix files reappearing in listings after being renamed (Nick\n        Craig-Wood)\n      - Fix moved files disappearing from listings between remotes\n        (Nick Craig-Wood)\n    - Netstorage\n      - Fix missing MD5 hash after uploading a file (Nick\n        Craig-Wood)\n    - Onedrive\n      - Add support for no admin mode (TaterLi)\n      - Treat non-2xx preauth download as error (ifloppy)\n      - Download malware-flagged files via Graph Prefer header\n        (ifloppy)\n    - Opendrive\n      - Fix uploaded objects returning the wrong hash and modtime\n        (Nick Craig-Wood)\n    - Oracleobjectstorage\n      - Fix crash when downloading objects with unknown length\n        (Nick Craig-Wood)\n      - Add --oos-decompress flag to download gzip-encoded files\n        (Nick Craig-Wood)\n    - Pixeldrain\n      - Fix incorrect modtime and missing hash after uploading a\n        file (Nick Craig-Wood)\n    - Protondrive\n      - Implement proper retry logic (tomholford)\n      - Fix gopenpgp: invalid data: user ID signature with wrong\n        type on custom-domain account (Nick Craig-Wood)\n      - Fix long hangs on permanent validation failures (Nick\n        Craig-Wood)\n      - Fix incorrect modtime after uploading a file (Nick\n        Craig-Wood)\n    - Putio\n      - Fix incorrect modtime after setting a file's modtime (Nick\n        Craig-Wood)\n      - Fix sync deletions failing with 400 TRASH_LOCK_TIMEOUT\n        errors (Nick Craig-Wood)\n    - Quatrix\n      - Fix incorrect modtime after uploading a file (Nick\n        Craig-Wood)\n    - S3\n      - Add Zero Services (ZERO-Z3) provider (Zero Services GmbH)\n      - Add Scality (RING / ARTESCA) provider (Dzmitry Nianakhau)\n    - Seafile\n      - Fix rclone sync files with identical size again and again\n        (TowyTowy)\n    - SFTP\n      - Add --sftp-pin-host-key - Trust On First Use host key\n        pinning (Nick Craig-Wood)\n      - Add --sftp-encoding support (Puneet Dixit)\n      - Don't retry permanent connection errors (Nick Craig-Wood)\n      - Allow silencing no hostkey validation warning (Noah Zalev)\n      - Fix cmd shell execution of paths containing\n        variable-expansion or newline characters (Nick Craig-Wood)\n    - Shade\n      - Retry server errors instead of failing the transfer (Nick\n        Craig-Wood)\n      - Fix uploads failing with EOF when completing multipart\n        uploads (Nick Craig-Wood)\n    - Smb\n      - Fix Kerberos credentials being reloaded for every\n        connection (Nick Craig-Wood)\n      - Fix TCP connection leak when connection setup fails (Nick\n        Craig-Wood)\n      - Fix server-side move of directories with special characters\n        in the name (Nick Craig-Wood)\n      - Fix spurious \"Directory already exists\" errors when moving\n        directories (Nick Craig-Wood)\n    - Ulozto\n      - Fix server side moves between differently rooted remotes\n        losing files (Nick Craig-Wood)\n    - WebDAV\n      - Fix incorrect modtime after setting a file's modtime (Nick\n        Craig-Wood)\n    - Yandex\n      - Fix 500 errors by waiting for uploads to complete before\n        setting modtime (Nick Craig-Wood)\n      - Fix missing MD5 hash after uploading a file (Nick\n        Craig-Wood)\n      - Fix modtime randomly reverting to the upload time after\n        upload (Nick Craig-Wood)\n      - Add --yandex-upload-wait to fix 500 errors when uploading\n        (Nick Craig-Wood)\n    - Zoho\n      - Honour Retry-After header on 429 (Erol Ozcan)\n      - Add --zoho-tpslimit and --zoho-tpslimit-burst (Erol Ozcan)\n      - Log throttling once per episode at NOTICE (Erol Ozcan)\n      - Rate limit repeated listings of the same folder (Erol\n        Ozcan)\n      - Fix flaky folder list limiter test under concurrent\n        listings (Nick Craig-Wood)\n      - Fix large file overwrite creating a duplicate instead of\n        replacing (Erol Ozcan)\n      - Treat R008 unauthorized as directory not found (Erol Ozcan)\n      - Preserve root_folder_id on reconnect and allow setting it\n        (Erol Ozcan)\n","modified":"2026-10-01T18:23:12.143628024Z","published":"2026-09-28T15:31:12Z","related":["CVE-2026-33818","CVE-2026-39821","CVE-2026-46600","CVE-2026-46603","CVE-2026-56853","CVE-2026-56854","CVE-2026-56855","CVE-2026-56858","CVE-2026-56859","CVE-2026-56860","CVE-2026-56862","CVE-2026-78662"],"upstream":["CVE-2026-33818","CVE-2026-39821","CVE-2026-46600","CVE-2026-46603","CVE-2026-56853","CVE-2026-56854","CVE-2026-56855","CVE-2026-56858","CVE-2026-56859","CVE-2026-56860","CVE-2026-56862","CVE-2026-78662"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279548"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33818"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46603"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56853"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56858"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56860"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78662"}],"affected":[{"package":{"name":"rclone","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/rclone&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.75.1-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"rclone-bash-completion":"1.75.1-bp160.1.1","rclone-zsh-completion":"1.75.1-bp160.1.1","rclone":"1.75.1-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21999-1.json"}}],"schema_version":"1.9.0"}