<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:01:43 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32029 — OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32029</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw used left-most `X-Forwarded-For` values when requests came from configured trusted proxies. In proxy chains that append/preserve header values, this could let attacker-controlled header content influence security decisions tied to client IP.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected: `&amp;lt;= 2026.2.19-2`
- Patched: `2026.2.21` (planned next release)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Possible client-IP spoofing in security-sensitive paths (for example auth rate-limit identity and local/private classification) for deployments behind trusted proxies with non-recommended forwarding behavior.&lt;/p&gt;
&lt;p&gt;### Scope Note&lt;/p&gt;
&lt;p&gt;OpenClaw docs recommend reverse proxies overwrite (not append/preserve) inbound forwarding headers. This condition reduces severity.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `07039dc089e51589a213ec0d16f8d6f2cd871fa1`
- `8877bfd11ec7760b115b2d0d7500a45da2749747`&lt;/p&gt;
&lt;p&gt;### Release Process Note&lt;/p&gt;
&lt;p&gt;`patched_versions` is pre-set to the planned next release (`2026.2.21`). After npm release is out, publish this advisory.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AnthonyDiSanti for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw used left-most `X-Forwarded-For` values when requests came from configured trusted proxies. In proxy chains that append/preserve header values, this could let attacker-controlled header content influence security decisions tied to client IP.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected: `&amp;lt;= 2026.2.19-2`
- Patched: `2026.2.21` (planned next release)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Possible client-IP spoofing in security-sensitive paths (for example auth rate-limit identity and local/private classification) for deployments behind trusted proxies with non-recommended forwarding behavior.&lt;/p&gt;
&lt;p&gt;### Scope Note&lt;/p&gt;
&lt;p&gt;OpenClaw docs recommend reverse proxies overwrite (not append/preserve) inbound forwarding headers. This condition reduces severity.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `07039dc089e51589a213ec0d16f8d6f2cd871fa1`
- `8877bfd11ec7760b115b2d0d7500a45da2749747`&lt;/p&gt;
&lt;p&gt;### Release Process Note&lt;/p&gt;
&lt;p&gt;`patched_versions` is pre-set to the planned next release (`2026.2.21`). After npm release is out, publish this advisory.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AnthonyDiSanti for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32029</guid>
    </item>
    <item>
      <title>cnvd-2026-14827</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-14827</link>
      <description>cnvd-2026-14827</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-14827</guid>
    </item>
    <item>
      <title>EUVD-2026-329425</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329425</link>
      <description>EUVD-2026-329425</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329425</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32029</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32029</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate from configured trusted proxies, allowing attackers to spoof client IP addresses. In proxy chains that append or preserve header values, attackers can inject malicious header content to influence security decisions including authentication rate-limiting and IP-based access controls.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate from configured trusted proxies, allowing attackers to spoof client IP addresses. In proxy chains that append or preserve header values, attackers can inject malicious header content to influence security decisions including authentication rate-limiting and IP-based access controls.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32029</guid>
    </item>
    <item>
      <title>GHSA-2rgf-hm63-5qph — OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2rgf-hm63-5qph</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw used left-most `X-Forwarded-For` values when requests came from configured trusted proxies. In proxy chains that append/preserve header values, this could let attacker-controlled header content influence security decisions tied to client IP.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected: `&amp;lt;= 2026.2.19-2`
- Patched: `2026.2.21` (planned next release)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Possible client-IP spoofing in security-sensitive paths (for example auth rate-limit identity and local/private classification) for deployments behind trusted proxies with non-recommended forwarding behavior.&lt;/p&gt;
&lt;p&gt;### Scope Note&lt;/p&gt;
&lt;p&gt;OpenClaw docs recommend reverse proxies overwrite (not append/preserve) inbound forwarding headers. This condition reduces severity.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `07039dc089e51589a213ec0d16f8d6f2cd871fa1`
- `8877bfd11ec7760b115b2d0d7500a45da2749747`&lt;/p&gt;
&lt;p&gt;### Release Process Note&lt;/p&gt;
&lt;p&gt;`patched_versions` is pre-set to the planned next release (`2026.2.21`). After npm release is out, publish this advisory.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AnthonyDiSanti for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw used left-most `X-Forwarded-For` values when requests came from configured trusted proxies. In proxy chains that append/preserve header values, this could let attacker-controlled header content influence security decisions tied to client IP.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected: `&amp;lt;= 2026.2.19-2`
- Patched: `2026.2.21` (planned next release)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Possible client-IP spoofing in security-sensitive paths (for example auth rate-limit identity and local/private classification) for deployments behind trusted proxies with non-recommended forwarding behavior.&lt;/p&gt;
&lt;p&gt;### Scope Note&lt;/p&gt;
&lt;p&gt;OpenClaw docs recommend reverse proxies overwrite (not append/preserve) inbound forwarding headers. This condition reduces severity.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `07039dc089e51589a213ec0d16f8d6f2cd871fa1`
- `8877bfd11ec7760b115b2d0d7500a45da2749747`&lt;/p&gt;
&lt;p&gt;### Release Process Note&lt;/p&gt;
&lt;p&gt;`patched_versions` is pre-set to the planned next release (`2026.2.21`). After npm release is out, publish this advisory.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AnthonyDiSanti for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2rgf-hm63-5qph</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0472 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0472</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0472</guid>
    </item>
  </channel>
</rss>
