GHSA-82c6-8mfc-c23h · Severity: medium — A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file...
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.
Conclusion & alert: CVE-2024-12086 is rated High Exploit Risk (68.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.91%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-29 | 2.02% | 1.91% | -0.11% |
| 2 | 2026-05-28 | 1.65% | 2.02% | +0.37% |
| 3 | 2026-05-26 | — | 1.65% | — |
Full EPSS history (20 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.1 | 3.1 | MEDIUM |
|
1.6 | 4.0 | [email protected] |
| 6.8 | 3.1 | MEDIUM |
|
2.2 | 4.0 | [email protected] |
GHSA-82c6-8mfc-c23h · Severity: medium — A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file...
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-12086: 1 source package rows (rsync); 25 state rows across 6 repos (3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 6, open 19. | https://security.alpinelinux.org/vuln/CVE-2024-12086 |
debian
|
not yet assigned | CVE-2024-12086 not yet assigned priority: Debian including 1 source packages (rsync), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2024-12086 |
gentoo
|
high | CVE-2024-12086: 1 GLSA(s) (202501-01), 1 atom(s) (net-misc/rsync); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2024-12086 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2024-12086 |
suse
|
medium | CVE-2024-12086 severity moderate: SUSE including 259 source package names (15.7.20.5.1:rsync-3.2.7-150600.3.8.1, 2.0.4-3.5.253:rsync-3.2.3-150400.3.17.1, …), 585 product×package rows across 320 product lines (Container bci/kiwi, Container suse/hpc/warewulf4-x86_64/sle-hpc-node, … (320 product lines)): Fixed 354, Known Affected 231. | https://www.suse.com/security/cve/CVE-2024-12086/ |
ubuntu
|
medium | CVE-2024-12086 medium priority: Ubuntu including 1 source packages (rsync), 8 status rows across 8 suites (bionic, focal, jammy, noble, oracular, trusty, upstream, xenial): released 8. | https://ubuntu.com/security/CVE-2024-12086 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| samba | rsync | <= 3.3.0 | cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.0 | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 6.0 | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 7.0 | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 9.0 | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 10.0 | cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* |
| almalinux | almalinux | 8.0 | cpe:2.3:o:almalinux:almalinux:8.0:-:*:*:*:*:*:* |
| almalinux | almalinux | 9.0 | cpe:2.3:o:almalinux:almalinux:9.0:-:*:*:*:*:*:* |
| almalinux | almalinux | 10.0 | cpe:2.3:o:almalinux:almalinux:10.0:-:*:*:*:*:*:* |
| archlinux | arch_linux | — | cpe:2.3:o:archlinux:arch_linux:-:*:*:*:*:*:*:* |
| gentoo | linux | — | cpe:2.3:o:gentoo:linux:-:*:*:*:*:*:*:* |
| nixos | nixos | < 24.11 | cpe:2.3:o:nixos:nixos:*:*:*:*:*:*:*:* |
| suse | suse_linux | — | cpe:2.3:o:suse:suse_linux:-:*:*:*:*:*:*:* |
| tritondatacenter | smartos | < 20250123 | cpe:2.3:o:tritondatacenter:smartos:*:*:*:*:*:*:*:* |