rclone v1.75.2 released
By SecBurg
rclone syncs files and directories to and from a huge range of cloud storage providers - “rsync for cloud storage”.
The new v1.75.2 release is mostly a security-focused update. The build moves to Go 1.26.9 and a newer golang.org/x/net to address several CVEs, and grpc was updated as well. Credential leaks on redirects are closed for b2 (account token and SSE-C key) and webdav (the headers option), --header values are no longer sent after an HTTPS-to-HTTP downgrade, and // paths can no longer move a remote to another host.
Path traversal above the served directory is fixed in serve nfs and serve webdav, and .rclonelink names can no longer escape the root with --links. serve s3 got a bunch of fixes too (presigned URLs that could copy any object, auth-proxy users seeing each other’s uploads, bypassed multipart buffer limits), along with new --multipart-max-uploads, --multipart-streaming-buffer-total and --metadata-max-objects flags.
More highlights:
selfupdate no longer trusts unsigned data in the signed SHA256SUMS file
rc: job/status and job/list now require authentication
lib/http: OPTIONS requests now require authentication
pcloud: OAuth callbacks must include state and come from pCloud hosts
Fixes for truncated or corrupted uploads after retries or early source EOF in several backends
Retries for "network is unreachable" and "network is down" errors
Full changelog is available on the rclone changelog page, release notes and downloads on the GitHub release page.
Happy cloning! :-)