bin/rclone_linux_amd64 is upstream rclone v1.75.1, which pins
google.golang.org/grpc at v1.84.0-dev.0.20260723093437-b6eac429d7b6. That
pseudo-version is affected by CVE-2026-84445 / GHSA-2v4p-qf9q-27wj (HIGH,
gRPC-Go denial of service). Trivy lists the fix as
v1.85.0-dev.0.20260825072537-93e31b48545e, which rclone master already carries
but no rclone release does yet — v1.75.1 (2026-09-04) is still the newest:
$ curl -s https://raw.githubusercontent.com/rclone/rclone/master/go.mod | grep grpc
google.golang.org/grpc v1.85.0-dev.0.20260825072537-93e31b48545e // indirect
$ curl -s https://raw.githubusercontent.com/rclone/rclone/v1.75.1/go.mod | grep grpc
google.golang.org/grpc v1.84.0-dev.0.20260723093437-b6eac429d7b6 // indirect
So there is nothing to do here until upstream ships a release. Until then the
finding is accepted in two places, both expiring 2026-12-01:
.trivyignore.yaml in this repo, scoped to bin/rclone_linux_amd64.
owncloud/server-release's root ignore file, scoped to
apps/migrate_to_ocis/bin/rclone_linux_amd64. The assembled-bundle scan in
spec-check.yml is a separate gate and does not read this repo's file, so the
acceptance has to exist on both sides.
Why it is acceptable in the meantime: the panic is in the xDS routing
interceptor, which is installed only by servers constructed with
xds.NewGRPCServer(), and is triggered by an inbound RPC carrying neither
:authority nor Host. grpc is an indirect dependency of rclone's Google
backends; this app never speaks gRPC at all, let alone serves it. It shells out
to rclone sync between two WebDAV remotes
(StateMigrateFiles::buildRCloneSyncCommand()) and to rclone obscure
(StateMigrateFiles::RCloneObscure()), and uses neither rclone serve nor the
rc API.
What to do when the rclone release lands
- Confirm the new release's
go.mod carries grpc >= the fixed pseudo-version —
read go.mod, not the release notes.
- Replace
bin/rclone_linux_amd64 with the upstream linux-amd64 binary from
that release, keeping mode 100755. Trivy's gobinary analyzer skips
non-executable files, so a lost exec bit turns the scan green by accident
rather than red.
- Diff the new binary's
-v output against v1.75.1's on the app's exact flag
set before calling the bump safe. StateMigrateFiles fails a user's
migration on any rclone output line containing NOTICE/WARNING/ERROR, and
rclone's -v stats banner is itself a bare NOTICE: line. v1.75.0 and
v1.75.1 happened to match; a future release need not.
- Drop the acceptance from
.trivyignore.yaml here and from
owncloud/server-release, and confirm both scans are green with no entry for
this CVE rather than assuming it.
If no rclone release has appeared by 2026-12-01, the two expired_at dates lapse
and both scans go red on purpose — that is the reminder to re-decide, not a
regression.
bin/rclone_linux_amd64is upstream rclone v1.75.1, which pinsgoogle.golang.org/grpcatv1.84.0-dev.0.20260723093437-b6eac429d7b6. Thatpseudo-version is affected by CVE-2026-84445 / GHSA-2v4p-qf9q-27wj (HIGH,
gRPC-Go denial of service). Trivy lists the fix as
v1.85.0-dev.0.20260825072537-93e31b48545e, which rclone master already carriesbut no rclone release does yet — v1.75.1 (2026-09-04) is still the newest:
So there is nothing to do here until upstream ships a release. Until then the
finding is accepted in two places, both expiring 2026-12-01:
.trivyignore.yamlin this repo, scoped tobin/rclone_linux_amd64.owncloud/server-release's root ignore file, scoped toapps/migrate_to_ocis/bin/rclone_linux_amd64. The assembled-bundle scan inspec-check.ymlis a separate gate and does not read this repo's file, so theacceptance has to exist on both sides.
Why it is acceptable in the meantime: the panic is in the xDS routing
interceptor, which is installed only by servers constructed with
xds.NewGRPCServer(), and is triggered by an inbound RPC carrying neither:authoritynorHost. grpc is an indirect dependency of rclone's Googlebackends; this app never speaks gRPC at all, let alone serves it. It shells out
to
rclone syncbetween two WebDAV remotes(
StateMigrateFiles::buildRCloneSyncCommand()) and torclone obscure(
StateMigrateFiles::RCloneObscure()), and uses neitherrclone servenor therc API.
What to do when the rclone release lands
go.modcarries grpc >= the fixed pseudo-version —read
go.mod, not the release notes.bin/rclone_linux_amd64with the upstreamlinux-amd64binary fromthat release, keeping mode 100755. Trivy's gobinary analyzer skips
non-executable files, so a lost exec bit turns the scan green by accident
rather than red.
-voutput against v1.75.1's on the app's exact flagset before calling the bump safe.
StateMigrateFilesfails a user'smigration on any rclone output line containing
NOTICE/WARNING/ERROR, andrclone's
-vstats banner is itself a bareNOTICE:line. v1.75.0 andv1.75.1 happened to match; a future release need not.
.trivyignore.yamlhere and fromowncloud/server-release, and confirm both scans are green with no entry forthis CVE rather than assuming it.
If no rclone release has appeared by 2026-12-01, the two
expired_atdates lapseand both scans go red on purpose — that is the reminder to re-decide, not a
regression.