
🚨Critical - rsync Daemon IP Spoofing via PROXY Protocol Header (CVE-2026-53791) The rsync daemon before 3.5.0 trusts the source address in a PROXY protocol header without validation. An unauthenticated attacker who can connect directly to rsyncd can send a crafted PROXY header with a forged source IP to bypass hosts allow / hosts deny rules and reach modules that should be blocked by their real IP. This is an access-control bypass rather than direct code execution, so the impact depends on what the exposed rsync modules allow, read-only mirror versus writable. It applies where the daemon accepts PROXY protocol. CVSS 9.1. 👉Upgrade rsync to 3.5.0; don't rely on IP allow/deny alone (use rsync auth), and only accept PROXY headers from trusted upstreams.
Post summary
The post announces a critical rsync daemon flaw that allows IP spoofing via PROXY headers, offers technical details, and recommends upgrading to 3.5.0 with additional mitigations.
