<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:38:12.291211+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35626</id>
    <title>BREW-openclaw-cli-CVE-2026-35626 — OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling</title>
    <updated>2026-10-03T10:38:12.370179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary
Voice Call webhook handling buffered request bodies before provider signature checks, enabling bounded unauthenticated resource exhaustion.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &lt; 2026.3.22
- Fixed: &gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`</p>
<p>## Fix Commit(s)
- `651dc7450b68a5396a009db78ef9382633707ead`</p>
<p>## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.</p>
<p>## Code-Level Confirmation
- extensions/voice-call/src/webhook.ts now enforces header gating and shared pre-auth body caps before reading attacker-controlled request bodies.
- extensions/voice-call/src/webhook.test.ts ships regression coverage for missing-signature, oversize, and timeout pre-auth webhook cases.</p>
<p>OpenClaw thanks @SEORY0 for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-21188</id>
    <title>cnvd-2026-21188</title>
    <updated>2026-10-03T10:38:12.370244+00:00</updated>
    <content>cnvd-2026-21188</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-21188"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329504</id>
    <title>EUVD-2026-329504</title>
    <updated>2026-10-03T10:38:12.370264+00:00</updated>
    <content>EUVD-2026-329504</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329504"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35626</id>
    <title>fkie_cve-2026-35626</title>
    <updated>2026-10-03T10:38:12.370276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to exhaust server resources without authentication by bypassing signature validation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rm59-992w-x2mv</id>
    <title>GHSA-rm59-992w-x2mv — OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling</title>
    <updated>2026-10-03T10:38:12.370298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary
Voice Call webhook handling buffered request bodies before provider signature checks, enabling bounded unauthenticated resource exhaustion.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &lt; 2026.3.22
- Fixed: &gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`</p>
<p>## Fix Commit(s)
- `651dc7450b68a5396a009db78ef9382633707ead`</p>
<p>## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.</p>
<p>## Code-Level Confirmation
- extensions/voice-call/src/webhook.ts now enforces header gating and shared pre-auth body caps before reading attacker-controlled request bodies.
- extensions/voice-call/src/webhook.test.ts ships regression coverage for missing-signature, oversize, and timeout pre-auth webhook cases.</p>
<p>OpenClaw thanks @SEORY0 for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rm59-992w-x2mv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0856</id>
    <title>WID-SEC-W-2026-0856 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:38:12.370327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen – sogar Administratorrechte – zu erlangen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0856"/>
  </entry>
</feed>
