Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-41356

OpenClaw < 2026.3.31 - Incomplete WebSocket Session Termination in device.token.rotate_CVE-2026-41356

OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously compromised credentia...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41348

OpenClaw < 2026.3.31 - Group DM Channel Allowlist Bypass via Discord Slash Commands_CVE-2026-41348

OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths that fail to enforce group...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41347

OpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator Endpoints_CVE-2026-41347

OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site requ...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41341

OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension_CVE-2026-41341

OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messag...

OpenClaw OpenClaw CVE
LOW 3.7 CVE-2026-2708

Libsoup: libsoup: http request smuggling via duplicate content-length headers_CVE-2026-2708

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/sou...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 2.3 CVE-2026-41908

OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route_CVE-2026-41908

OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without ...

OpenClaw OpenClaw CVE
LOW 3.5 CVE-2026-4512

WP reCaptcha by WebDesignBy < 2.0 – Admin+ Stored XSS_CVE-2026-4512

The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript stri...

Unknown reCaptcha by WebDesignBy CVE
LOW 3.2 CVE-2026-41988

CVE-2026-41988_CVE-2026-41988

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID versio...

uuidjs uuid CVE
LOW 2.7 CVE-2026-1272

IBM Guardium Data Protection is affected by multiple vulnerabilities_CVE-2026-1272

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.

IBM Guardium Data Protection 12.0 CVE
LOW 2.1 CVE-2026-6019

BaseCookie.js_output() does not neutralize embedded characters_CVE-2026-6019

http.cookies.Morsel.js_output() returns an inline snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser...

Python Software Foundation CPython CVE