<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:14:37 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-35624 — OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35624</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Nextcloud Talk room authorization matched on collidable room names instead of the stable room token, allowing policy confusion across similarly named rooms.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &amp;lt; 2026.3.22
- Fixed: &amp;gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a47722de7e3c9cbda8d5512747ca7e3bb8f6ee66`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- extensions/nextcloud-talk/src/inbound.ts now resolves allowlist policy from roomToken-backed room identity.
- extensions/nextcloud-talk/src/policy.ts now keys room authorization on stable room tokens instead of display names.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @zpbrent for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Nextcloud Talk room authorization matched on collidable room names instead of the stable room token, allowing policy confusion across similarly named rooms.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &amp;lt; 2026.3.22
- Fixed: &amp;gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a47722de7e3c9cbda8d5512747ca7e3bb8f6ee66`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- extensions/nextcloud-talk/src/inbound.ts now resolves allowlist policy from roomToken-backed room identity.
- extensions/nextcloud-talk/src/policy.ts now keys room authorization on stable room tokens instead of display names.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @zpbrent for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35624</guid>
    </item>
    <item>
      <title>cnvd-2026-21186</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-21186</link>
      <description>cnvd-2026-21186</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-21186</guid>
    </item>
    <item>
      <title>EUVD-2026-329502</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329502</link>
      <description>EUVD-2026-329502</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329502</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35624</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35624</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain unauthorized access to protected Nextcloud Talk rooms.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain unauthorized access to protected Nextcloud Talk rooms.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35624</guid>
    </item>
    <item>
      <title>GHSA-xhq5-45pm-2gjr — OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xhq5-45pm-2gjr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Nextcloud Talk room authorization matched on collidable room names instead of the stable room token, allowing policy confusion across similarly named rooms.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &amp;lt; 2026.3.22
- Fixed: &amp;gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a47722de7e3c9cbda8d5512747ca7e3bb8f6ee66`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- extensions/nextcloud-talk/src/inbound.ts now resolves allowlist policy from roomToken-backed room identity.
- extensions/nextcloud-talk/src/policy.ts now keys room authorization on stable room tokens instead of display names.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @zpbrent for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Nextcloud Talk room authorization matched on collidable room names instead of the stable room token, allowing policy confusion across similarly named rooms.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &amp;lt; 2026.3.22
- Fixed: &amp;gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a47722de7e3c9cbda8d5512747ca7e3bb8f6ee66`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- extensions/nextcloud-talk/src/inbound.ts now resolves allowlist policy from roomToken-backed room identity.
- extensions/nextcloud-talk/src/policy.ts now keys room authorization on stable room tokens instead of display names.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @zpbrent for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xhq5-45pm-2gjr</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0856 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0856</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen – sogar Administratorrechte – zu erlangen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen – sogar Administratorrechte – zu erlangen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0856</guid>
    </item>
  </channel>
</rss>
