telegraf-1.39
github.com/rclone/rclone
9.8
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable component is github.com/rclone/rclone, used only by the remotefile output plugin for VFS file operations; the vulnerable RC HTTP server (fs/rc/rcserver) is never imported or started. The minimum fixed version, rclone v1.73.5, removes the fs.LogOutput API that the plugin still uses (including on upstream's master branch), so bumping the dependency breaks the build until upstream adapts. Pending upstream fix.
Status