<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:02:57 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32011 — OpenClaw has pre-auth webhook body parsing that can enable unauthenticated slow-request DoS</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32011</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;OpenClaw webhook handlers for BlueBubbles and Google Chat accepted and parsed request bodies before authentication and signature checks on vulnerable releases. This allowed unauthenticated clients to hold parser work open with slow/oversized request bodies and degrade availability (slow-request DoS).&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected releases: `&amp;lt;= 2026.3.1`
- Latest published vulnerable version at triage time: `2026.3.1` (npm)
- Fixed release: `2026.3.2` (released)&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `d3e8b17aa6432536806b4853edc7939d891d0f25`&lt;/p&gt;
&lt;p&gt;## Mitigation&lt;/p&gt;
&lt;p&gt;Upgrade to `2026.3.2` (or newer). The fix enforces auth-before-body for affected webhook paths, adds strict pre-auth body/time budgets, and introduces shared in-flight/request guardrails with regression coverage.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;OpenClaw webhook handlers for BlueBubbles and Google Chat accepted and parsed request bodies before authentication and signature checks on vulnerable releases. This allowed unauthenticated clients to hold parser work open with slow/oversized request bodies and degrade availability (slow-request DoS).&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected releases: `&amp;lt;= 2026.3.1`
- Latest published vulnerable version at triage time: `2026.3.1` (npm)
- Fixed release: `2026.3.2` (released)&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `d3e8b17aa6432536806b4853edc7939d891d0f25`&lt;/p&gt;
&lt;p&gt;## Mitigation&lt;/p&gt;
&lt;p&gt;Upgrade to `2026.3.2` (or newer). The fix enforces auth-before-body for affected webhook paths, adds strict pre-auth body/time budgets, and introduces shared in-flight/request guardrails with regression coverage.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32011</guid>
    </item>
    <item>
      <title>cnvd-2026-14825</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-14825</link>
      <description>cnvd-2026-14825</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-14825</guid>
    </item>
    <item>
      <title>EUVD-2026-329408</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329408</link>
      <description>EUVD-2026-329408</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329408</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32011</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32011</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request bodies before performing authentication and signature validation. Unauthenticated attackers can exploit this by sending slow or oversized request bodies to exhaust parser resources and degrade service availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request bodies before performing authentication and signature validation. Unauthenticated attackers can exploit this by sending slow or oversized request bodies to exhaust parser resources and degrade service availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32011</guid>
    </item>
    <item>
      <title>GHSA-x4vp-4235-65hg — OpenClaw has pre-auth webhook body parsing that can enable unauthenticated slow-request DoS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x4vp-4235-65hg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;OpenClaw webhook handlers for BlueBubbles and Google Chat accepted and parsed request bodies before authentication and signature checks on vulnerable releases. This allowed unauthenticated clients to hold parser work open with slow/oversized request bodies and degrade availability (slow-request DoS).&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected releases: `&amp;lt;= 2026.3.1`
- Latest published vulnerable version at triage time: `2026.3.1` (npm)
- Fixed release: `2026.3.2` (released)&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `d3e8b17aa6432536806b4853edc7939d891d0f25`&lt;/p&gt;
&lt;p&gt;## Mitigation&lt;/p&gt;
&lt;p&gt;Upgrade to `2026.3.2` (or newer). The fix enforces auth-before-body for affected webhook paths, adds strict pre-auth body/time budgets, and introduces shared in-flight/request guardrails with regression coverage.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;OpenClaw webhook handlers for BlueBubbles and Google Chat accepted and parsed request bodies before authentication and signature checks on vulnerable releases. This allowed unauthenticated clients to hold parser work open with slow/oversized request bodies and degrade availability (slow-request DoS).&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected releases: `&amp;lt;= 2026.3.1`
- Latest published vulnerable version at triage time: `2026.3.1` (npm)
- Fixed release: `2026.3.2` (released)&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `d3e8b17aa6432536806b4853edc7939d891d0f25`&lt;/p&gt;
&lt;p&gt;## Mitigation&lt;/p&gt;
&lt;p&gt;Upgrade to `2026.3.2` (or newer). The fix enforces auth-before-body for affected webhook paths, adds strict pre-auth body/time budgets, and introduces shared in-flight/request guardrails with regression coverage.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x4vp-4235-65hg</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0573 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0573</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0573</guid>
    </item>
  </channel>
</rss>
