<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:58:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-380337</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-380337</link>
      <description>EUVD-2026-380337</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-380337</guid>
    </item>
    <item>
      <title>fkie_cve-2026-28465</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28465</link>
      <description>&lt;p&gt;OpenClaw&amp;#39;s voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw&amp;#39;s voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-28465</guid>
    </item>
    <item>
      <title>GHSA-3m3q-x3gj-f79x — OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3m3q-x3gj-f79x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @openclaw/voice-call, npm: @clawdbot/voice-call&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;This issue affects the optional voice-call plugin only. It is not enabled by default; it only applies to installations where the plugin is installed and enabled.&lt;/p&gt;
&lt;p&gt;- Package: `@openclaw/voice-call`
- Vulnerable versions: `&amp;lt; 2026.2.3`
- Patched versions: `&amp;gt;= 2026.2.3`&lt;/p&gt;
&lt;p&gt;Legacy package name (if you are still using it):&lt;/p&gt;
&lt;p&gt;- Package: `@clawdbot/voice-call`
- Vulnerable versions: `&amp;lt;= 2026.1.24`
- Patched versions: none published under this package name; migrate to `@openclaw/voice-call`&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In certain reverse-proxy / forwarding setups, webhook verification can be bypassed if untrusted forwarded headers are accepted.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An external party may be able to send voice-call webhook requests that are accepted as valid, which can result in spoofed webhook events being processed.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;Some deployments implicitly trusted forwarded headers (for example `Forwarded` / `X-Forwarded-*`) when determining request properties used during webhook verification. If those headers are not overwritten by a trusted proxy, a client can supply them directly and influence verification.&lt;/p&gt;
&lt;p&gt;## Resolution&lt;/p&gt;
&lt;p&gt;Ignore forwarded headers by default unless explicitly trusted and allowlisted in configuration. Keep any loopback-only development bypass restricted to local development only. Upgrade to a patched version.&lt;/p&gt;
&lt;p&gt;If you cannot upgrade immediately, strip `Forwarded` and `X-Forwarded-*` headers at the edge so clients cannot supply them directly.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @openclaw/voice-call, npm: @clawdbot/voice-call&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;This issue affects the optional voice-call plugin only. It is not enabled by default; it only applies to installations where the plugin is installed and enabled.&lt;/p&gt;
&lt;p&gt;- Package: `@openclaw/voice-call`
- Vulnerable versions: `&amp;lt; 2026.2.3`
- Patched versions: `&amp;gt;= 2026.2.3`&lt;/p&gt;
&lt;p&gt;Legacy package name (if you are still using it):&lt;/p&gt;
&lt;p&gt;- Package: `@clawdbot/voice-call`
- Vulnerable versions: `&amp;lt;= 2026.1.24`
- Patched versions: none published under this package name; migrate to `@openclaw/voice-call`&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In certain reverse-proxy / forwarding setups, webhook verification can be bypassed if untrusted forwarded headers are accepted.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An external party may be able to send voice-call webhook requests that are accepted as valid, which can result in spoofed webhook events being processed.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;Some deployments implicitly trusted forwarded headers (for example `Forwarded` / `X-Forwarded-*`) when determining request properties used during webhook verification. If those headers are not overwritten by a trusted proxy, a client can supply them directly and influence verification.&lt;/p&gt;
&lt;p&gt;## Resolution&lt;/p&gt;
&lt;p&gt;Ignore forwarded headers by default unless explicitly trusted and allowlisted in configuration. Keep any loopback-only development bypass restricted to local development only. Upgrade to a patched version.&lt;/p&gt;
&lt;p&gt;If you cannot upgrade immediately, strip `Forwarded` and `X-Forwarded-*` headers at the edge so clients cannot supply them directly.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3m3q-x3gj-f79x</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0424 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0424</link>
      <description>&lt;p&gt;Ein Angreifer kann diese Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann diese Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0424</guid>
    </item>
  </channel>
</rss>
