<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T05:45:36.607860+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-380337</id>
    <title>EUVD-2026-380337</title>
    <updated>2026-10-04T05:45:36.649046+00:00</updated>
    <content>EUVD-2026-380337</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-380337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28465</id>
    <title>fkie_cve-2026-28465</title>
    <updated>2026-10-04T05:45:36.649086+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-28465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3m3q-x3gj-f79x</id>
    <title>GHSA-3m3q-x3gj-f79x — OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations</title>
    <updated>2026-10-04T05:45:36.649123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @openclaw/voice-call, npm: @clawdbot/voice-call</p>
<p>## Affected Packages / Versions</p>
<p>This issue affects the optional voice-call plugin only. It is not enabled by default; it only applies to installations where the plugin is installed and enabled.</p>
<p>- Package: `@openclaw/voice-call`
- Vulnerable versions: `&lt; 2026.2.3`
- Patched versions: `&gt;= 2026.2.3`</p>
<p>Legacy package name (if you are still using it):</p>
<p>- Package: `@clawdbot/voice-call`
- Vulnerable versions: `&lt;= 2026.1.24`
- Patched versions: none published under this package name; migrate to `@openclaw/voice-call`</p>
<p>## Summary</p>
<p>In certain reverse-proxy / forwarding setups, webhook verification can be bypassed if untrusted forwarded headers are accepted.</p>
<p>## Impact</p>
<p>An external party may be able to send voice-call webhook requests that are accepted as valid, which can result in spoofed webhook events being processed.</p>
<p>## Root Cause</p>
<p>Some deployments implicitly trusted forwarded headers (for example `Forwarded` / `X-Forwarded-*`) when determining request properties used during webhook verification. If those headers are not overwritten by a trusted proxy, a client can supply them directly and influence verification.</p>
<p>## Resolution</p>
<p>Ignore forwarded headers by default unless explicitly trusted and allowlisted in configuration. Keep any loopback-only development bypass restricted to local development only. Upgrade to a patched version.</p>
<p>If you cannot upgrade immediately, strip `Forwarded` and `X-Forwarded-*` headers at the edge so clients cannot supply them directly.</p>
<p>## Fix Commit(s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3m3q-x3gj-f79x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0424</id>
    <title>WID-SEC-W-2026-0424 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-04T05:45:36.649177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann diese Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder andere, nicht näher bezeichnete Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0424"/>
  </entry>
</feed>
