Common Weakness Enumeration

CWE-799

Allowed-with-Review

Improper Control of Interaction Frequency

Abstraction: Class · Status: Incomplete

The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

127 vulnerabilities reference this CWE, most recent first.

CVE-2026-100603 (GCVE-0-2026-100603)

Vulnerability from cvelistv5 – Published: 2026-09-26 13:22 – Updated: 2026-09-28 17:05
VLAI
Title
ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports
Summary
ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that skill from the catalog without any moderator decision. Because the reporter quota counts only reports filed against visible targets, the same accounts can repeat the process against additional skills; official skills are not exempt. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. The fix (PR #3681) is included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 17:05 UTC
CWE
  • CWE-799 - Improper Control of Interaction Frequency
Impacted products
Vendor Product Version
openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
Create a notification for this product.
Date Public
2026-09-11 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-100603",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-28T17:05:07.198454Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-28T17:05:43.542Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "clawhub",
          "vendor": "openclaw",
          "versions": [
            {
              "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
              "status": "affected",
              "version": "0",
              "versionType": "git"
            },
            {
              "status": "unaffected",
              "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
              "versionType": "git"
            }
          ]
        }
      ],
      "datePublic": "2026-09-11T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that skill from the catalog without any moderator decision. Because the reporter quota counts only reports filed against visible targets, the same accounts can repeat the process against additional skills; official skills are not exempt. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. The fix (PR #3681) is included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-26T13:22:47.730Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-5jj4-m8c9-gwcq)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-5jj4-m8c9-gwcq"
        },
        {
          "name": "Patch Commit",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
        },
        {
          "name": "VulnCheck Advisory: ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/clawhub-before-8c2de6c506-skill-hiding-via-coordinated-reports"
        }
      ],
      "title": "ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-100603",
    "datePublished": "2026-09-26T13:22:47.730Z",
    "dateReserved": "2026-09-26T01:04:47.561Z",
    "dateUpdated": "2026-09-28T17:05:43.542Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93650 (GCVE-0-2026-93650)

Vulnerability from cvelistv5 – Published: 2026-09-18 18:15 – Updated: 2026-09-18 19:47
VLAI
Title
Saleor throttling.py get_client_ip excessive authentication
Summary
A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits "IP can be spoofed in most deployments" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that "[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly".
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 19:47 UTC
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
  • CWE-799 - Improper Control of Interaction Frequency
References
Impacted products
Vendor Product Version
n/a Saleor Affected: 3.20.118
Affected: 3.21.0
Affected: 3.21.1
Affected: 3.21.2
Affected: 3.21.3
Affected: 3.21.4
Affected: 3.21.5
Affected: 3.21.6
Affected: 3.21.7
Affected: 3.21.8
Affected: 3.21.9
Affected: 3.21.10
Affected: 3.21.11
Affected: 3.21.12
Affected: 3.21.13
Affected: 3.21.14
Affected: 3.21.15
Affected: 3.21.16
Affected: 3.21.17
Affected: 3.21.18
Affected: 3.21.19
Affected: 3.21.20
Affected: 3.21.21
Affected: 3.21.22
Affected: 3.21.23
Affected: 3.21.24
Affected: 3.21.25
Affected: 3.21.26
Affected: 3.21.27
Affected: 3.21.28
Affected: 3.21.29
Affected: 3.21.30
Affected: 3.21.31
Affected: 3.21.32
Affected: 3.21.33
Affected: 3.21.34
Affected: 3.21.35
Affected: 3.21.36
Affected: 3.21.37
Affected: 3.21.38
Affected: 3.21.39
Affected: 3.21.40
Affected: 3.21.41
Affected: 3.21.42
Affected: 3.21.43
Affected: 3.21.44
Affected: 3.21.45
Affected: 3.21.46
Affected: 3.21.47
Affected: 3.21.48
Affected: 3.21.49
Affected: 3.21.50
Affected: 3.21.51
Affected: 3.21.52
Affected: 3.21.53
Affected: 3.21.54
Affected: 3.22.0
Affected: 3.22.1
Affected: 3.22.2
Affected: 3.22.3
Affected: 3.22.4
Affected: 3.22.5
Affected: 3.22.6
Affected: 3.22.7
Affected: 3.22.8
Affected: 3.22.9
Affected: 3.22.10
Affected: 3.22.11
Affected: 3.22.12
Affected: 3.22.13
Affected: 3.22.14
Affected: 3.22.15
Affected: 3.22.16
Affected: 3.22.17
Affected: 3.22.18
Affected: 3.22.19
Affected: 3.22.20
Affected: 3.22.21
Affected: 3.22.22
Affected: 3.22.23
Affected: 3.22.24
Affected: 3.22.25
Affected: 3.22.26
Affected: 3.22.27
Affected: 3.22.28
Affected: 3.22.29
Affected: 3.22.30
Affected: 3.22.31
Affected: 3.22.32
Affected: 3.22.33
Affected: 3.22.34
Affected: 3.22.35
Affected: 3.22.36
Affected: 3.22.37
Affected: 3.22.38
Affected: 3.22.39
Affected: 3.22.40
Affected: 3.22.41
Affected: 3.22.42
Affected: 3.22.43
Affected: 3.22.44
Affected: 3.22.45
Affected: 3.22.46
Affected: 3.22.47
Affected: 3.23.0
Affected: 3.23.1
Affected: 3.23.2
Affected: 3.23.3
Affected: 3.23.4
Affected: 3.23.5
Affected: 3.23.6
Affected: 3.23.7
Affected: 3.23.8
Affected: 3.23.9
Affected: 3.23.10
Affected: 3.23.11
Affected: 3.23.12
Affected: 3.23.13
Affected: 3.23.14
    cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93650",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-18T19:47:42.986649Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-18T19:47:52.282Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*"
          ],
          "product": "Saleor",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "3.20.118"
            },
            {
              "status": "affected",
              "version": "3.21.0"
            },
            {
              "status": "affected",
              "version": "3.21.1"
            },
            {
              "status": "affected",
              "version": "3.21.2"
            },
            {
              "status": "affected",
              "version": "3.21.3"
            },
            {
              "status": "affected",
              "version": "3.21.4"
            },
            {
              "status": "affected",
              "version": "3.21.5"
            },
            {
              "status": "affected",
              "version": "3.21.6"
            },
            {
              "status": "affected",
              "version": "3.21.7"
            },
            {
              "status": "affected",
              "version": "3.21.8"
            },
            {
              "status": "affected",
              "version": "3.21.9"
            },
            {
              "status": "affected",
              "version": "3.21.10"
            },
            {
              "status": "affected",
              "version": "3.21.11"
            },
            {
              "status": "affected",
              "version": "3.21.12"
            },
            {
              "status": "affected",
              "version": "3.21.13"
            },
            {
              "status": "affected",
              "version": "3.21.14"
            },
            {
              "status": "affected",
              "version": "3.21.15"
            },
            {
              "status": "affected",
              "version": "3.21.16"
            },
            {
              "status": "affected",
              "version": "3.21.17"
            },
            {
              "status": "affected",
              "version": "3.21.18"
            },
            {
              "status": "affected",
              "version": "3.21.19"
            },
            {
              "status": "affected",
              "version": "3.21.20"
            },
            {
              "status": "affected",
              "version": "3.21.21"
            },
            {
              "status": "affected",
              "version": "3.21.22"
            },
            {
              "status": "affected",
              "version": "3.21.23"
            },
            {
              "status": "affected",
              "version": "3.21.24"
            },
            {
              "status": "affected",
              "version": "3.21.25"
            },
            {
              "status": "affected",
              "version": "3.21.26"
            },
            {
              "status": "affected",
              "version": "3.21.27"
            },
            {
              "status": "affected",
              "version": "3.21.28"
            },
            {
              "status": "affected",
              "version": "3.21.29"
            },
            {
              "status": "affected",
              "version": "3.21.30"
            },
            {
              "status": "affected",
              "version": "3.21.31"
            },
            {
              "status": "affected",
              "version": "3.21.32"
            },
            {
              "status": "affected",
              "version": "3.21.33"
            },
            {
              "status": "affected",
              "version": "3.21.34"
            },
            {
              "status": "affected",
              "version": "3.21.35"
            },
            {
              "status": "affected",
              "version": "3.21.36"
            },
            {
              "status": "affected",
              "version": "3.21.37"
            },
            {
              "status": "affected",
              "version": "3.21.38"
            },
            {
              "status": "affected",
              "version": "3.21.39"
            },
            {
              "status": "affected",
              "version": "3.21.40"
            },
            {
              "status": "affected",
              "version": "3.21.41"
            },
            {
              "status": "affected",
              "version": "3.21.42"
            },
            {
              "status": "affected",
              "version": "3.21.43"
            },
            {
              "status": "affected",
              "version": "3.21.44"
            },
            {
              "status": "affected",
              "version": "3.21.45"
            },
            {
              "status": "affected",
              "version": "3.21.46"
            },
            {
              "status": "affected",
              "version": "3.21.47"
            },
            {
              "status": "affected",
              "version": "3.21.48"
            },
            {
              "status": "affected",
              "version": "3.21.49"
            },
            {
              "status": "affected",
              "version": "3.21.50"
            },
            {
              "status": "affected",
              "version": "3.21.51"
            },
            {
              "status": "affected",
              "version": "3.21.52"
            },
            {
              "status": "affected",
              "version": "3.21.53"
            },
            {
              "status": "affected",
              "version": "3.21.54"
            },
            {
              "status": "affected",
              "version": "3.22.0"
            },
            {
              "status": "affected",
              "version": "3.22.1"
            },
            {
              "status": "affected",
              "version": "3.22.2"
            },
            {
              "status": "affected",
              "version": "3.22.3"
            },
            {
              "status": "affected",
              "version": "3.22.4"
            },
            {
              "status": "affected",
              "version": "3.22.5"
            },
            {
              "status": "affected",
              "version": "3.22.6"
            },
            {
              "status": "affected",
              "version": "3.22.7"
            },
            {
              "status": "affected",
              "version": "3.22.8"
            },
            {
              "status": "affected",
              "version": "3.22.9"
            },
            {
              "status": "affected",
              "version": "3.22.10"
            },
            {
              "status": "affected",
              "version": "3.22.11"
            },
            {
              "status": "affected",
              "version": "3.22.12"
            },
            {
              "status": "affected",
              "version": "3.22.13"
            },
            {
              "status": "affected",
              "version": "3.22.14"
            },
            {
              "status": "affected",
              "version": "3.22.15"
            },
            {
              "status": "affected",
              "version": "3.22.16"
            },
            {
              "status": "affected",
              "version": "3.22.17"
            },
            {
              "status": "affected",
              "version": "3.22.18"
            },
            {
              "status": "affected",
              "version": "3.22.19"
            },
            {
              "status": "affected",
              "version": "3.22.20"
            },
            {
              "status": "affected",
              "version": "3.22.21"
            },
            {
              "status": "affected",
              "version": "3.22.22"
            },
            {
              "status": "affected",
              "version": "3.22.23"
            },
            {
              "status": "affected",
              "version": "3.22.24"
            },
            {
              "status": "affected",
              "version": "3.22.25"
            },
            {
              "status": "affected",
              "version": "3.22.26"
            },
            {
              "status": "affected",
              "version": "3.22.27"
            },
            {
              "status": "affected",
              "version": "3.22.28"
            },
            {
              "status": "affected",
              "version": "3.22.29"
            },
            {
              "status": "affected",
              "version": "3.22.30"
            },
            {
              "status": "affected",
              "version": "3.22.31"
            },
            {
              "status": "affected",
              "version": "3.22.32"
            },
            {
              "status": "affected",
              "version": "3.22.33"
            },
            {
              "status": "affected",
              "version": "3.22.34"
            },
            {
              "status": "affected",
              "version": "3.22.35"
            },
            {
              "status": "affected",
              "version": "3.22.36"
            },
            {
              "status": "affected",
              "version": "3.22.37"
            },
            {
              "status": "affected",
              "version": "3.22.38"
            },
            {
              "status": "affected",
              "version": "3.22.39"
            },
            {
              "status": "affected",
              "version": "3.22.40"
            },
            {
              "status": "affected",
              "version": "3.22.41"
            },
            {
              "status": "affected",
              "version": "3.22.42"
            },
            {
              "status": "affected",
              "version": "3.22.43"
            },
            {
              "status": "affected",
              "version": "3.22.44"
            },
            {
              "status": "affected",
              "version": "3.22.45"
            },
            {
              "status": "affected",
              "version": "3.22.46"
            },
            {
              "status": "affected",
              "version": "3.22.47"
            },
            {
              "status": "affected",
              "version": "3.23.0"
            },
            {
              "status": "affected",
              "version": "3.23.1"
            },
            {
              "status": "affected",
              "version": "3.23.2"
            },
            {
              "status": "affected",
              "version": "3.23.3"
            },
            {
              "status": "affected",
              "version": "3.23.4"
            },
            {
              "status": "affected",
              "version": "3.23.5"
            },
            {
              "status": "affected",
              "version": "3.23.6"
            },
            {
              "status": "affected",
              "version": "3.23.7"
            },
            {
              "status": "affected",
              "version": "3.23.8"
            },
            {
              "status": "affected",
              "version": "3.23.9"
            },
            {
              "status": "affected",
              "version": "3.23.10"
            },
            {
              "status": "affected",
              "version": "3.23.11"
            },
            {
              "status": "affected",
              "version": "3.23.12"
            },
            {
              "status": "affected",
              "version": "3.23.13"
            },
            {
              "status": "affected",
              "version": "3.23.14"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "ZAST.AI (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits \"IP can be spoofed in most deployments\" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that \"[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly\"."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 2.6,
            "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-18T18:15:10.080Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-407477 | Saleor throttling.py get_client_ip excessive authentication",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/407477"
        },
        {
          "name": "VDB-407477 | CTI Indicators (IOB, IOC, TTP, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/407477/cti"
        },
        {
          "name": "CVE-2026-93650 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-93650"
        },
        {
          "name": "Submit #933655 | saleor \u003c=3.23.14 Improper Restriction of Excessive Authentication Attempts",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/933655"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/zast-ai/vulnerability-reports/blob/main/saleor/bruteforce.md"
        },
        {
          "tags": [
            "issue-tracking"
          ],
          "url": "https://github.com/saleor/saleor/issues/19203"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/saleor/saleor/"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-18T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-18T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-18T15:13:21.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "Saleor throttling.py get_client_ip excessive authentication",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-93650",
    "datePublished": "2026-09-18T18:15:10.080Z",
    "dateReserved": "2026-09-18T13:07:36.010Z",
    "dateUpdated": "2026-09-18T19:47:52.282Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-85586 (GCVE-0-2026-85586)

Vulnerability from cvelistv5 – Published: 2026-09-04 11:29 – Updated: 2026-09-10 15:09
VLAI
Title
phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter
Summary
phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 14:28 UTC
CWE
  • CWE-799 - Improper Control of Interaction Frequency
References
Impacted products
Vendor Product Version
thorsten phpMyFAQ Affected: 0 , < 4.1.8 (semver)
Unaffected: 4.1.8 (semver)
    cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-08-20 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-85586",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-10T14:28:22.626469Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-10T15:09:44.277Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "phpMyFAQ",
          "vendor": "thorsten",
          "versions": [
            {
              "lessThan": "4.1.8",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.1.8",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.1.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "skeletonsec"
        }
      ],
      "datePublic": "2026-08-20T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to \u0027now\u0027 in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "LOW"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-04T11:29:53.397Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-72vj-pvm4-mm7x)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-72vj-pvm4-mm7x"
        },
        {
          "name": "VulnCheck Advisory: phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-captcha-bypass-via-store-parameter"
        }
      ],
      "title": "phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-85586",
    "datePublished": "2026-09-04T11:29:53.397Z",
    "dateReserved": "2026-09-04T10:56:22.465Z",
    "dateUpdated": "2026-09-10T15:09:44.277Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-84461 (GCVE-0-2026-84461)

Vulnerability from cvelistv5 – Published: 2026-09-25 18:21 – Updated: 2026-09-25 18:41
VLAI
Title
Zammad: Missing rate limiting allows password brute-forcing during two-factor login
Summary
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response also revealed whether a guess was correct, even before two-factor authentication was checked. This made it possible to brute-force weak or reused passwords. This issue is fixed in version 7.1.2.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-25 18:41 UTC
CWE
  • CWE-203 - Observable Discrepancy
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
  • CWE-799 - Improper Control of Interaction Frequency
References
Impacted products
Vendor Product Version
zammad zammad Affected: < 7.1.2
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-84461",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-25T18:41:07.364423Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-25T18:41:14.822Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "zammad",
          "vendor": "zammad",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 7.1.2"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad\u0027s normal lockout or rate limiting. The response also revealed whether a guess was correct, even before two-factor authentication was checked. This made it possible to brute-force weak or reused passwords. This issue is fixed in version 7.1.2."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-203",
              "description": "CWE-203: Observable Discrepancy",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "CWE-307: Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "CWE-799: Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-25T18:21:20.015Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/zammad/zammad/security/advisories/GHSA-6vh5-pfp2-5rmh",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/zammad/zammad/security/advisories/GHSA-6vh5-pfp2-5rmh"
        },
        {
          "name": "https://github.com/zammad/zammad/commit/d51254f1c6da13f6ee27636a5c82e53f7e59666b",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/zammad/zammad/commit/d51254f1c6da13f6ee27636a5c82e53f7e59666b"
        }
      ],
      "source": {
        "advisory": "GHSA-6vh5-pfp2-5rmh",
        "discovery": "UNKNOWN"
      },
      "title": "Zammad: Missing rate limiting allows password brute-forcing during two-factor login"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-84461",
    "datePublished": "2026-09-25T18:21:20.015Z",
    "dateReserved": "2026-09-01T20:05:09.424Z",
    "dateUpdated": "2026-09-25T18:41:14.822Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-75773 (GCVE-0-2026-75773)

Vulnerability from cvelistv5 – Published: 2026-08-18 11:00 – Updated: 2026-08-19 13:40 X_Open Source
VLAI
Title
karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication
Summary
A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been made public and could be used. Upgrading to version 0.33.0 is sufficient to fix this issue. The patch is identified as f7d042971d0d2bcc7119654830cf1eb93eabbf24. It is advisable to upgrade the affected component.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-19 13:39 UTC
CWE
  • CWE-307 - Improper Restriction of Excessive Authentication Attempts
  • CWE-799 - Improper Control of Interaction Frequency
Impacted products
Vendor Product Version
karakeep-app karakeep Affected: 0.1
Affected: 0.2
Affected: 0.3
Affected: 0.4
Affected: 0.5
Affected: 0.6
Affected: 0.7
Affected: 0.8
Affected: 0.9
Affected: 0.10
Affected: 0.11
Affected: 0.12
Affected: 0.13
Affected: 0.14
Affected: 0.15
Affected: 0.16
Affected: 0.17
Affected: 0.18
Affected: 0.19
Affected: 0.20
Affected: 0.21
Affected: 0.22
Affected: 0.23
Affected: 0.24
Affected: 0.25
Affected: 0.26
Affected: 0.27
Affected: 0.28
Affected: 0.29
Affected: 0.30
Affected: 0.31
Affected: 0.32.0
Unaffected: 0.33.0
    cpe:2.3:a:karakeep-app:karakeep:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-75773",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-19T13:39:58.695815Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-19T13:40:09.189Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:karakeep-app:karakeep:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Login Endpoint"
          ],
          "product": "karakeep",
          "vendor": "karakeep-app",
          "versions": [
            {
              "status": "affected",
              "version": "0.1"
            },
            {
              "status": "affected",
              "version": "0.2"
            },
            {
              "status": "affected",
              "version": "0.3"
            },
            {
              "status": "affected",
              "version": "0.4"
            },
            {
              "status": "affected",
              "version": "0.5"
            },
            {
              "status": "affected",
              "version": "0.6"
            },
            {
              "status": "affected",
              "version": "0.7"
            },
            {
              "status": "affected",
              "version": "0.8"
            },
            {
              "status": "affected",
              "version": "0.9"
            },
            {
              "status": "affected",
              "version": "0.10"
            },
            {
              "status": "affected",
              "version": "0.11"
            },
            {
              "status": "affected",
              "version": "0.12"
            },
            {
              "status": "affected",
              "version": "0.13"
            },
            {
              "status": "affected",
              "version": "0.14"
            },
            {
              "status": "affected",
              "version": "0.15"
            },
            {
              "status": "affected",
              "version": "0.16"
            },
            {
              "status": "affected",
              "version": "0.17"
            },
            {
              "status": "affected",
              "version": "0.18"
            },
            {
              "status": "affected",
              "version": "0.19"
            },
            {
              "status": "affected",
              "version": "0.20"
            },
            {
              "status": "affected",
              "version": "0.21"
            },
            {
              "status": "affected",
              "version": "0.22"
            },
            {
              "status": "affected",
              "version": "0.23"
            },
            {
              "status": "affected",
              "version": "0.24"
            },
            {
              "status": "affected",
              "version": "0.25"
            },
            {
              "status": "affected",
              "version": "0.26"
            },
            {
              "status": "affected",
              "version": "0.27"
            },
            {
              "status": "affected",
              "version": "0.28"
            },
            {
              "status": "affected",
              "version": "0.29"
            },
            {
              "status": "affected",
              "version": "0.30"
            },
            {
              "status": "affected",
              "version": "0.31"
            },
            {
              "status": "affected",
              "version": "0.32.0"
            },
            {
              "status": "unaffected",
              "version": "0.33.0"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "ZAST.AI (VulDB User)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been made public and could be used. Upgrading to version 0.33.0 is sufficient to fix this issue. The patch is identified as f7d042971d0d2bcc7119654830cf1eb93eabbf24. It is advisable to upgrade the affected component."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 2.6,
            "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-307",
              "description": "Improper Restriction of Excessive Authentication Attempts",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-18T11:00:12.342Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-391519 | karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/391519"
        },
        {
          "name": "VDB-391519 | CTI Indicators (IOB, IOC, TTP, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/391519/cti"
        },
        {
          "name": "CVE-2026-75773 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-75773"
        },
        {
          "name": "Submit #877731 | karakeep-app karakeep  \u003e= 0.3.0, \u003c= 0.32.0 Improper Restriction of Excessive Authentication Attempts",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/877731"
        },
        {
          "tags": [
            "exploit",
            "issue-tracking"
          ],
          "url": "https://github.com/karakeep-app/karakeep/issues/2919"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/karakeep-app/karakeep/commit/f7d042971d0d2bcc7119654830cf1eb93eabbf24"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/karakeep-app/karakeep/releases/tag/mcp/v0.33.0"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/karakeep-app/karakeep/"
        }
      ],
      "tags": [
        "x_open-source"
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-08-18T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-08-18T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-08-18T06:35:40.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication",
      "x_generator": [
        "VulDB PVTS v202608"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-75773",
    "datePublished": "2026-08-18T11:00:12.342Z",
    "dateReserved": "2026-08-18T04:30:29.332Z",
    "dateUpdated": "2026-08-19T13:40:09.189Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-54738 (GCVE-0-2026-54738)

Vulnerability from cvelistv5 – Published: 2026-08-19 20:27 – Updated: 2026-08-21 21:48
VLAI
Title
Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo
Summary
Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/rate_limit/mod.rs. Lemmy's bundled docker/nginx.conf uses $proxy_add_x_forwarded_for instead of $remote_addr, which appends the real client address to an X-Forwarded-For value supplied by the client. An unauthenticated attacker can therefore place a different spoofed address first on each request and receive a new rate-limit bucket, bypassing limits on POST /api/v4/account/auth/register, POST /api/v4/account/auth/login, POST /api/v4/post, POST /api/v4/comment, GET /api/v4/search, POST /api/v4/image, and POST /api/v4/account/import_settings. This permits excessive account creation, brute-force attempts, spam, scraping, uploads, and repeated imports. This issue is fixed in versions 0.19.19 and 1.0.0-beta.1.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 21:09 UTC
CWE
  • CWE-799 - Improper Control of Interaction Frequency
Impacted products
Vendor Product Version
LemmyNet lemmy Affected: < 0.19.19
Affected: >= 1.0.0-alpha.5, < 1.0.0-beta.1
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-54738",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-21T21:09:45.793083Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-21T21:48:26.962Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "lemmy",
          "vendor": "LemmyNet",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 0.19.19"
            },
            {
              "status": "affected",
              "version": "\u003e= 1.0.0-alpha.5, \u003c 1.0.0-beta.1"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/rate_limit/mod.rs. Lemmy\u0027s bundled docker/nginx.conf uses $proxy_add_x_forwarded_for instead of $remote_addr, which appends the real client address to an X-Forwarded-For value supplied by the client. An unauthenticated attacker can therefore place a different spoofed address first on each request and receive a new rate-limit bucket, bypassing limits on POST /api/v4/account/auth/register, POST /api/v4/account/auth/login, POST /api/v4/post, POST /api/v4/comment, GET /api/v4/search, POST /api/v4/image, and POST /api/v4/account/import_settings. This permits excessive account creation, brute-force attempts, spam, scraping, uploads, and repeated imports. This issue is fixed in versions 0.19.19 and 1.0.0-beta.1."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "CWE-799: Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-19T20:27:45.162Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/LemmyNet/lemmy/security/advisories/GHSA-2hrg-7x4g-9vpg",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/LemmyNet/lemmy/security/advisories/GHSA-2hrg-7x4g-9vpg"
        },
        {
          "name": "https://github.com/LemmyNet/lemmy/pull/6574",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/LemmyNet/lemmy/pull/6574"
        },
        {
          "name": "https://github.com/LemmyNet/lemmy/pull/6575",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/LemmyNet/lemmy/pull/6575"
        },
        {
          "name": "https://github.com/LemmyNet/lemmy/commit/41513c89ceecee719bff05acfe613e3b1e85f23c",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/LemmyNet/lemmy/commit/41513c89ceecee719bff05acfe613e3b1e85f23c"
        },
        {
          "name": "https://github.com/LemmyNet/lemmy/commit/8b5b2aa78417b53ff3622c01f5bed2f1590f3b82",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/LemmyNet/lemmy/commit/8b5b2aa78417b53ff3622c01f5bed2f1590f3b82"
        },
        {
          "name": "https://github.com/LemmyNet/lemmy/releases/tag/0.19.19",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/LemmyNet/lemmy/releases/tag/0.19.19"
        },
        {
          "name": "https://github.com/LemmyNet/lemmy/releases/tag/1.0.0-beta.1",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/LemmyNet/lemmy/releases/tag/1.0.0-beta.1"
        },
        {
          "name": "https://join-lemmy.org/news/2026-06-09_-_Lemmy_Release_v0.19.19",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://join-lemmy.org/news/2026-06-09_-_Lemmy_Release_v0.19.19"
        }
      ],
      "source": {
        "advisory": "GHSA-2hrg-7x4g-9vpg",
        "discovery": "UNKNOWN"
      },
      "title": "Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-54738",
    "datePublished": "2026-08-19T20:27:45.162Z",
    "dateReserved": "2026-06-15T23:07:33.233Z",
    "dateUpdated": "2026-08-21T21:48:26.962Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-54594 (GCVE-0-2026-54594)

Vulnerability from cvelistv5 – Published: 2026-09-17 19:51 – Updated: 2026-09-18 20:09
VLAI
Title
OmniBlocks: Spamming in Discussions tab possible via disc.yml
Summary
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was already converted or otherwise suppressing duplicate runs. A user who creates one off-topic issue and repeatedly edits its description before conversion completes can therefore cause multiple discussions to be created for the same issue, producing discussion spam and additional moderation work. This issue is fixed with commit 627e0f0a16a7d74b09128106b57dd7e85d2545df.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 20:09 UTC
CWE
  • CWE-799 - Improper Control of Interaction Frequency
Impacted products
Vendor Product Version
OmniBlocks monorepo Affected: < OmniBlocks
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-54594",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-18T20:09:08.371650Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-18T20:09:27.955Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/OmniBlocks/monorepo/security/advisories/GHSA-pq9c-3595-72jq"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "monorepo",
          "vendor": "OmniBlocks",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c OmniBlocks"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was already converted or otherwise suppressing duplicate runs. A user who creates one off-topic issue and repeatedly edits its description before conversion completes can therefore cause multiple discussions to be created for the same issue, producing discussion spam and additional moderation work. This issue is fixed with commit 627e0f0a16a7d74b09128106b57dd7e85d2545df."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "LOW"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "CWE-799: Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-17T19:51:32.309Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/OmniBlocks/monorepo/security/advisories/GHSA-pq9c-3595-72jq",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/OmniBlocks/monorepo/security/advisories/GHSA-pq9c-3595-72jq"
        },
        {
          "name": "https://github.com/OmniBlocks/monorepo/commit/2953ef77649fc3c206fc1ee306f74cedc31b67e3",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/OmniBlocks/monorepo/commit/2953ef77649fc3c206fc1ee306f74cedc31b67e3"
        },
        {
          "name": "https://github.com/OmniBlocks/monorepo/commit/627e0f0a16a7d74b09128106b57dd7e85d2545df",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/OmniBlocks/monorepo/commit/627e0f0a16a7d74b09128106b57dd7e85d2545df"
        }
      ],
      "source": {
        "advisory": "GHSA-pq9c-3595-72jq",
        "discovery": "UNKNOWN"
      },
      "title": "OmniBlocks: Spamming in Discussions tab possible via disc.yml"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-54594",
    "datePublished": "2026-09-17T19:51:32.309Z",
    "dateReserved": "2026-06-15T19:45:23.539Z",
    "dateUpdated": "2026-09-18T20:09:27.955Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-41346 (GCVE-0-2026-41346)

Vulnerability from cvelistv5 – Published: 2026-04-23 21:58 – Updated: 2026-04-24 16:39 X_Open Source
VLAI
Title
OpenClaw 2026.2.26 < 2026.3.31 - Denial of Service via Improper Pending Pairing Request Cap Enforcement
Summary
OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allowing attackers to exhaust the shared pending window. Remote attackers can submit pairing requests from other accounts to block new pairing challenges on unaffected accounts, causing denial of service.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-04-24 16:38 UTC
CWE
  • CWE-799 - Improper Control of Interaction Frequency
Impacted products
Vendor Product Version
OpenClaw OpenClaw Affected: 2026.2.26 , < 2026.3.31 (semver)
Unaffected: 2026.3.31 (semver)
    cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Create a notification for this product.
Date Public
2026-04-02 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-41346",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-04-24T16:38:52.186395Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-04-24T16:39:00.293Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:npm/openclaw",
          "product": "OpenClaw",
          "vendor": "OpenClaw",
          "versions": [
            {
              "lessThan": "2026.3.31",
              "status": "affected",
              "version": "2026.2.26",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "2026.3.31",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
                  "versionEndExcluding": "2026.3.31",
                  "versionStartIncluding": "2026.2.26",
                  "vulnerable": true
                }
              ],
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "smaeljaish771"
        },
        {
          "lang": "en",
          "type": "finder",
          "value": "KeenSecurityLab"
        }
      ],
      "datePublic": "2026-04-02T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allowing attackers to exhaust the shared pending window. Remote attackers can submit pairing requests from other accounts to block new pairing challenges on unaffected accounts, causing denial of service."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-23T21:58:05.227Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-wwfp-w96m-c6x8)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-wwfp-w96m-c6x8"
        },
        {
          "name": "Patch Commit",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/openclaw/openclaw/commit/9bc1f896c8cd325dd4761681e9bdb8c425f69785"
        },
        {
          "name": "VulnCheck Advisory: OpenClaw 2026.2.26 \u003c 2026.3.31 - Denial of Service via Improper Pending Pairing Request Cap Enforcement",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/openclaw-denial-of-service-via-improper-pending-pairing-request-cap-enforcement"
        }
      ],
      "tags": [
        "x_open-source"
      ],
      "title": "OpenClaw 2026.2.26 \u003c 2026.3.31 - Denial of Service via Improper Pending Pairing Request Cap Enforcement",
      "x_generator": {
        "engine": "vulncheck"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-41346",
    "datePublished": "2026-04-23T21:58:05.227Z",
    "dateReserved": "2026-04-20T14:05:09.184Z",
    "dateUpdated": "2026-04-24T16:39:00.293Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-41343 (GCVE-0-2026-41343)

Vulnerability from cvelistv5 – Published: 2026-04-23 21:58 – Updated: 2026-04-24 14:32 X_Open Source
VLAI
Title
OpenClaw < 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth Concurrency
Summary
OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers to cause transient availability loss. Remote attackers can flood the webhook endpoint with concurrent requests before signature verification to exhaust resources and degrade service availability.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-04-24 14:30 UTC
CWE
  • CWE-799 - Improper Control of Interaction Frequency
Impacted products
Vendor Product Version
OpenClaw OpenClaw Affected: 0 , < 2026.3.31 (semver)
Unaffected: 2026.3.31 (semver)
    cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Create a notification for this product.
Date Public
2026-03-31 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-41343",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-04-24T14:30:05.806622Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-04-24T14:32:21.869Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:npm/openclaw",
          "product": "OpenClaw",
          "vendor": "OpenClaw",
          "versions": [
            {
              "lessThan": "2026.3.31",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "2026.3.31",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
                  "versionEndExcluding": "2026.3.31",
                  "vulnerable": true
                }
              ],
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "Nathan (@nexrin)"
        },
        {
          "lang": "en",
          "type": "finder",
          "value": "KeenSecurityLab"
        }
      ],
      "datePublic": "2026-03-31T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers to cause transient availability loss. Remote attackers can flood the webhook endpoint with concurrent requests before signature verification to exhaust resources and degrade service availability."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-23T21:58:02.040Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-qcc3-jqwp-5vh2)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-qcc3-jqwp-5vh2"
        },
        {
          "name": "Patch Commit",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/openclaw/openclaw/commit/57c47d8c7fbf5a2e70cc4dec2380977968903cad"
        },
        {
          "name": "VulnCheck Advisory: OpenClaw \u003c 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth Concurrency",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/openclaw-denial-of-service-via-line-webhook-handler-pre-auth-concurrency"
        }
      ],
      "tags": [
        "x_open-source"
      ],
      "title": "OpenClaw \u003c 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth Concurrency",
      "x_generator": {
        "engine": "vulncheck"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-41343",
    "datePublished": "2026-04-23T21:58:02.040Z",
    "dateReserved": "2026-04-20T14:05:09.184Z",
    "dateUpdated": "2026-04-24T14:32:21.869Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-41333 (GCVE-0-2026-41333)

Vulnerability from cvelistv5 – Published: 2026-04-23 21:57 – Updated: 2026-04-24 13:35 X_Open Source
VLAI
Title
OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken
Summary
OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls and conduct brute force attacks against weak shared passwords.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-04-24 13:35 UTC
CWE
  • CWE-799 - Improper Control of Interaction Frequency
Impacted products
Vendor Product Version
OpenClaw OpenClaw Affected: 0 , < 2026.3.31 (semver)
Unaffected: 2026.3.31 (semver)
    cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Create a notification for this product.
Date Public
2026-03-31 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-41333",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-04-24T13:35:25.571994Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-04-24T13:35:46.057Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:npm/openclaw",
          "product": "OpenClaw",
          "vendor": "OpenClaw",
          "versions": [
            {
              "lessThan": "2026.3.31",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "2026.3.31",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
                  "versionEndExcluding": "2026.3.31",
                  "vulnerable": true
                }
              ],
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "KEXNA (@kexinoh)"
        }
      ],
      "datePublic": "2026-03-31T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls and conduct brute force attacks against weak shared passwords."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-799",
              "description": "Improper Control of Interaction Frequency",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-23T21:57:53.810Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-6p8r-6m93-557f)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-6p8r-6m93-557f"
        },
        {
          "name": "Patch Commit",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/openclaw/openclaw/commit/af0c0862f22ca4492406a3103d05e3628f94cbe9"
        },
        {
          "name": "VulnCheck Advisory: OpenClaw \u003c 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/openclaw-authentication-rate-limiting-bypass-via-fake-devicetoken"
        }
      ],
      "tags": [
        "x_open-source"
      ],
      "title": "OpenClaw \u003c 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken",
      "x_generator": {
        "engine": "vulncheck"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-41333",
    "datePublished": "2026-04-23T21:57:53.810Z",
    "dateReserved": "2026-04-20T14:03:06.199Z",
    "dateUpdated": "2026-04-24T13:35:46.057Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

No mitigation information available for this CWE.

No CAPEC attack patterns related to this CWE.