<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:46:45.225068+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-34505</id>
    <title>BREW-openclaw-cli-CVE-2026-34505 — OpenClaw: Zalo webhook rate limiting could be bypassed before secret validation</title>
    <updated>2026-10-03T14:46:45.287651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>### Summary</p>
<p>The Zalo webhook handler applied request rate limiting only after webhook authentication succeeded. Requests with an invalid secret returned `401` but did not count against the rate limiter, allowing repeated secret guesses without triggering `429`.</p>
<p>### Impact</p>
<p>This made brute-force guessing materially easier for weak but policy-compliant webhook secrets. Once the secret was guessed, an attacker could submit forged Zalo webhook traffic.</p>
<p>### Affected versions</p>
<p>`openclaw` `&lt;= 2026.3.11`</p>
<p>### Patch</p>
<p>Fixed in `openclaw` `2026.3.12`. Rate limiting now applies before successful authentication is required, closing the pre-auth brute-force gap. Users should update to `2026.3.12` or later and prefer strong webhook secrets.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-34505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-17182</id>
    <title>cnvd-2026-17182</title>
    <updated>2026-10-03T14:46:45.287712+00:00</updated>
    <content>cnvd-2026-17182</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-17182"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329492</id>
    <title>EUVD-2026-329492</title>
    <updated>2026-10-03T14:46:45.287730+00:00</updated>
    <content>EUVD-2026-329492</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329492"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34505</id>
    <title>fkie_cve-2026-34505</title>
    <updated>2026-10-03T14:46:45.287742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets. Attackers can submit repeated authentication requests with invalid secrets without triggering rate limit responses, enabling systematic secret guessing and subsequent forged webhook submission.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5m9r-p9g7-679c</id>
    <title>GHSA-5m9r-p9g7-679c — OpenClaw: Zalo webhook rate limiting could be bypassed before secret validation</title>
    <updated>2026-10-03T14:46:45.287764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>### Summary</p>
<p>The Zalo webhook handler applied request rate limiting only after webhook authentication succeeded. Requests with an invalid secret returned `401` but did not count against the rate limiter, allowing repeated secret guesses without triggering `429`.</p>
<p>### Impact</p>
<p>This made brute-force guessing materially easier for weak but policy-compliant webhook secrets. Once the secret was guessed, an attacker could submit forged Zalo webhook traffic.</p>
<p>### Affected versions</p>
<p>`openclaw` `&lt;= 2026.3.11`</p>
<p>### Patch</p>
<p>Fixed in `openclaw` `2026.3.12`. Rate limiting now applies before successful authentication is required, closing the pre-auth brute-force gap. Users should update to `2026.3.12` or later and prefer strong webhook secrets.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5m9r-p9g7-679c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</id>
    <title>WID-SEC-W-2026-0711 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:46:45.287790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711"/>
  </entry>
</feed>
