<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T17:07:18.759881+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32913</id>
    <title>BREW-openclaw-cli-CVE-2026-32913 — OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects</title>
    <updated>2026-10-07T17:07:18.838408+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>OpenClaw's `fetchWithSsrFGuard(...)` followed cross-origin redirects while preserving arbitrary caller-supplied headers except for a narrow denylist (`Authorization`, `Proxy-Authorization`, `Cookie`, `Cookie2`). This allowed custom authorization headers such as `X-Api-Key`, `Private-Token`, and similar sensitive headers to be forwarded to a different origin after a redirect.</p>
<p>The fix switches cross-origin redirect handling from a narrow sensitive-header denylist to a safe-header allowlist, so only benign headers such as content negotiation and cache validators survive an origin change.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw` (npm)
- Affected versions: `&lt;= 2026.3.2`
- Patched version: `2026.3.7`
- Latest published npm version at patch time: `2026.3.2`</p>
<p>## Impact</p>
<p>A remote service that could trigger a redirect across origins could receive custom authorization credentials attached by OpenClaw callers. This can expose API keys, bearer-style custom headers, or private token headers intended only for the original destination.</p>
<p>## Fix Commit(s)</p>
<p>- `46715371b0612a6f9114dffd1466941ac476cef5`</p>
<p>## Verification</p>
<p>- `pnpm check` passed
- `pnpm test:fast` passed
- Focused redirect regression tests passed
- `pnpm exec vitest run --config vitest.gateway.config.ts` still has unrelated current-`main` failures in `src/gateway/server-channels.test.ts` and `src/gateway/server-methods/agents-mutate.test.ts`</p>
<p>## Release Process Note</p>
<p>npm `2026.3.7` was published on March 8, 2026. Th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-16392</id>
    <title>cnvd-2026-16392</title>
    <updated>2026-10-07T17:07:18.838489+00:00</updated>
    <content>cnvd-2026-16392</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-16392"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336713</id>
    <title>EUVD-2026-336713</title>
    <updated>2026-10-07T17:07:18.838507+00:00</updated>
    <content>EUVD-2026-336713</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336713"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32913</id>
    <title>fkie_cve-2026-32913</title>
    <updated>2026-10-07T17:07:18.838519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6mgf-v5j7-45cr</id>
    <title>GHSA-6mgf-v5j7-45cr — OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects</title>
    <updated>2026-10-07T17:07:18.838542+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>OpenClaw's `fetchWithSsrFGuard(...)` followed cross-origin redirects while preserving arbitrary caller-supplied headers except for a narrow denylist (`Authorization`, `Proxy-Authorization`, `Cookie`, `Cookie2`). This allowed custom authorization headers such as `X-Api-Key`, `Private-Token`, and similar sensitive headers to be forwarded to a different origin after a redirect.</p>
<p>The fix switches cross-origin redirect handling from a narrow sensitive-header denylist to a safe-header allowlist, so only benign headers such as content negotiation and cache validators survive an origin change.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw` (npm)
- Affected versions: `&lt;= 2026.3.2`
- Patched version: `2026.3.7`
- Latest published npm version at patch time: `2026.3.2`</p>
<p>## Impact</p>
<p>A remote service that could trigger a redirect across origins could receive custom authorization credentials attached by OpenClaw callers. This can expose API keys, bearer-style custom headers, or private token headers intended only for the original destination.</p>
<p>## Fix Commit(s)</p>
<p>- `46715371b0612a6f9114dffd1466941ac476cef5`</p>
<p>## Verification</p>
<p>- `pnpm check` passed
- `pnpm test:fast` passed
- Focused redirect regression tests passed
- `pnpm exec vitest run --config vitest.gateway.config.ts` still has unrelated current-`main` failures in `src/gateway/server-channels.test.ts` and `src/gateway/server-methods/agents-mutate.test.ts`</p>
<p>## Release Process Note</p>
<p>npm `2026.3.7` was published on March 8, 2026. Th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6mgf-v5j7-45cr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0639</id>
    <title>WID-SEC-W-2026-0639 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-07T17:07:18.838580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0639"/>
  </entry>
</feed>
