Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.4 CVE-2026-42188

Geyser: Server-Side Request Forgery (SSRF) via Player Head Texture URL_CVE-2026-42188

Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerabili...

GeyserMC Geyser < 2.9.3 CVE
LOW 2.3 CVE-2026-42865

Inbox Zero: Cross-account cleaner email stream exposure_CVE-2026-42865

Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, whi...

elie222 inbox-zero < 2.29.3 CVE
LOW 2.1 CVE-2026-43969

Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1_CVE-2026-43969

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling v...

ninenines cowlib 2.9.0 CVE
LOW 3.7 CVE-2026-42874

Microdot: HTTP response splitting in Response.set_cookie()_CVE-2026-42874

Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its string arguments, and in pa...

miguelgrinberg microdot < 2.6.1 CVE
LOW 2.3 CVE-2026-5266

CVE-2026-5266_CVE-2026-5266

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerability is associated with prog...

Wikimedia Foundation Echo * CVE
LOW 2.3 CVE-2026-45000

OpenClaw < 2026.4.20 - Server-Side Request Forgery via Browser CDP Profile Creation_CVE-2026-45000

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy c...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-44998

OpenClaw < 2026.4.20 - Tool Policy Bypass via Bundled MCP/LSP Tools_CVE-2026-44998

OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-44997

OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions_CVE-2026-44997

OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions th...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-44993

OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions_CVE-2026-44993

OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as gro...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-44991

OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders_CVE-2026-44991

OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced...

OpenClaw OpenClaw CVE