rclone Infinite Scale TUS Creation Transport Error Under Investigation
An early warning has been issued regarding a potential issue in rclone that may cause a crash due to a transport failure during Infinite Scale TUS creation POST requests. The affected version is rclone (go) v1.74.0-240-ga0c09f1381ae93e2a9a33c529d170186c61ad058.
What happened
Reportedly, a transport failure during the initial Infinite Scale TUS creation POST in rclone can return a `(nil response, non-nil error)`. Rclone appears to dereference the nil response before processing the error, leading to a panic and potential crash in production environments.
This issue is currently under investigation. To assess your exposure, monitor for transport failures during Infinite Scale TUS creation POST requests. It is recommended to consider mitigating the impact by handling nil responses appropriately.
For more detailed information, please consult the primary sources: [GHSA-3x6r-wxxg-53vv](https://github.com/rclone/rclone/security/advisories/GHSA-3x6r-wxxg-53vv), [GHSA-2m8m-jhrm-w6j2](https://github.com/rclone/rclone/security/advisories/GHSA-2m8m-jhrm-w6j2), [GHSA-45pq-889g-fcgh](https://github.com/rclone/rclone/security/advisories/GHSA-45pq-889g-fcgh), and [GHSA-4vr5-p2gc-h23p](https://github.com/rclone/rclone/security/advisories/GHSA-4vr5-p2gc-h23p).
How 0Day mitigates this
rclone is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.