<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:36:26 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-35626 — OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35626</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Voice Call webhook handling buffered request bodies before provider signature checks, enabling bounded unauthenticated resource exhaustion.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &amp;lt; 2026.3.22
- Fixed: &amp;gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `651dc7450b68a5396a009db78ef9382633707ead`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- extensions/voice-call/src/webhook.ts now enforces header gating and shared pre-auth body caps before reading attacker-controlled request bodies.
- extensions/voice-call/src/webhook.test.ts ships regression coverage for missing-signature, oversize, and timeout pre-auth webhook cases.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @SEORY0 for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Voice Call webhook handling buffered request bodies before provider signature checks, enabling bounded unauthenticated resource exhaustion.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &amp;lt; 2026.3.22
- Fixed: &amp;gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `651dc7450b68a5396a009db78ef9382633707ead`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- extensions/voice-call/src/webhook.ts now enforces header gating and shared pre-auth body caps before reading attacker-controlled request bodies.
- extensions/voice-call/src/webhook.test.ts ships regression coverage for missing-signature, oversize, and timeout pre-auth webhook cases.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @SEORY0 for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35626</guid>
    </item>
    <item>
      <title>cnvd-2026-21188</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-21188</link>
      <description>cnvd-2026-21188</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-21188</guid>
    </item>
    <item>
      <title>EUVD-2026-329504</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329504</link>
      <description>EUVD-2026-329504</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329504</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35626</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35626</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to exhaust server resources without authentication by bypassing signature validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to exhaust server resources without authentication by bypassing signature validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35626</guid>
    </item>
    <item>
      <title>GHSA-rm59-992w-x2mv — OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rm59-992w-x2mv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Voice Call webhook handling buffered request bodies before provider signature checks, enabling bounded unauthenticated resource exhaustion.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &amp;lt; 2026.3.22
- Fixed: &amp;gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `651dc7450b68a5396a009db78ef9382633707ead`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- extensions/voice-call/src/webhook.ts now enforces header gating and shared pre-auth body caps before reading attacker-controlled request bodies.
- extensions/voice-call/src/webhook.test.ts ships regression coverage for missing-signature, oversize, and timeout pre-auth webhook cases.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @SEORY0 for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Voice Call webhook handling buffered request bodies before provider signature checks, enabling bounded unauthenticated resource exhaustion.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &amp;lt; 2026.3.22
- Fixed: &amp;gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `651dc7450b68a5396a009db78ef9382633707ead`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- extensions/voice-call/src/webhook.ts now enforces header gating and shared pre-auth body caps before reading attacker-controlled request bodies.
- extensions/voice-call/src/webhook.test.ts ships regression coverage for missing-signature, oversize, and timeout pre-auth webhook cases.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @SEORY0 for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rm59-992w-x2mv</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0856 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0856</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen – sogar Administratorrechte – zu erlangen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen – sogar Administratorrechte – zu erlangen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0856</guid>
    </item>
  </channel>
</rss>
