← Downloads

rsync 3.5.0

Package v3.5.0 x86_64 TAR.GZ August 13, 2026

rsync 3.5.0 is a major security release closing 33 CVEs found by a focused audit of path handling and the daemon protocol, alongside the usual efficient delta-transfer file synchronization.

Download TAR.GZ Project website ↗

Download Mirrors

Mirror Region Download
Samba.org (Official) Primary Global Download
rsync Home Global Download
rsync NEWS Global Download

rsync is the standard tool for synchronizing files between locations, and 3.5.0 is what its own maintainers call an “extraordinary release” because it closes 33 security issues at once. We covered why that number is what it is.

Upgrade first, read second

The 33 fixes came from a focused audit of path handling, the daemon protocol, and related code, plus fuzzing of the daemon protocol. This was not years of trickling reports; it was what happens when modern tooling gets pointed at code written before hostile network input was a routine assumption.

The one to check immediately is CVE-2026-53791, affecting daemons configured with proxy protocol = true, where a client could supply its own PROXY header and defeat host-based access controls.

grep -r "proxy protocol" /etc/rsyncd.conf /etc/rsyncd.d/ 2>/dev/null
rsync --version | head -1

A large share of the remaining fixes concern symlink handling and path confinement, where a crafted symlink or path could redirect an operation outside its intended directory.

Daemon mode versus SSH

The distinction matters for your exposure. Most of the memory-safety issues are reachable through the daemon protocol.

# Over SSH: the remote rsync runs as you, after authentication
rsync -avz -e ssh /srv/data/ user@backup:/srv/data/

# Daemon mode: rsyncd listens and speaks to whoever connects
rsync -avz /srv/data/ rsync://backup.example.com/data/

If you only use rsync over SSH, which is how most people use it, your exposure was much narrower. The daemon protocol is the part that talks to strangers.

Why rsync is still the answer

The delta-transfer algorithm is the reason. rsync compares source and destination and transfers only the differing blocks, so re-syncing a large file that changed slightly costs almost nothing.

# The flags most people want
rsync -avh --progress source/ destination/

# Mirror exactly, deleting what is no longer in the source
rsync -avh --delete source/ destination/

# Dry run first, always, when --delete is involved
rsync -avhn --delete source/ destination/

The trailing slash on the source is the classic trap: source/ copies the contents, source copies the directory itself.

Our rsync command builder generates the flags interactively, and scp, sftp, and rsync compared covers when each transport is right.

Verify Your Download

Source tarballs are published with GPG signatures at download.samba.org.