rsync 3.5 ships 33 security fixes at once, including a critical proxy protocol flaw
On August 13, 2026 the rsync team released version 3.5, closing 33 CVEs including a critical flaw (CVE-2026-53791) that let a client spoof its source address through the proxy protocol. If your backups run as root over SSH, this is the update to apply first.