|
531
|
5.3 |
MEDIUM
Network
|
-
|
-
|
OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media replay. Attackers can exploit recovered queued outbound media to bypass group too…
New
|
CWE-862
Missing Authorization
|
CVE-2026-43583
|
2026-05-7 06:20 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
532
|
8.8 |
HIGH
Network
|
-
|
-
|
OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment policy that allows operator-supplied overrides of high-risk interpreter startup …
New
|
CWE-184
Incomplete Blacklist
|
CVE-2026-43584
|
2026-05-7 06:20 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
533
|
8.1 |
HIGH
Network
|
-
|
-
|
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-reso…
New
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2026-43585
|
2026-05-7 06:20 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
534
|
9.8 |
CRITICAL
Network
|
-
|
-
|
OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptK…
New
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-44109
|
2026-05-7 06:20 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
535
|
8.8 |
HIGH
Network
|
-
|
-
|
OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that trusts DM pairing-store entries. Attackers with DM-paired sender IDs can exe…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-44110
|
2026-05-7 06:20 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
536
|
4.3 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allows callers to read any Markdown files within the workspace root. Attackers with…
New
|
CWE-183
Permissive List of Allowed Inputs
|
CVE-2026-44111
|
2026-05-7 06:20 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
537
|
5.3 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attacker…
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-44112
|
2026-05-7 06:20 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
538
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fuse: abort on fatal signal during sync init
When sync init is used and the server exits for some reason (error, crash)
while pro…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31713
|
2026-05-7 06:13 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
539
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid memory leak in f2fs_rename()
syzbot reported a f2fs bug as below:
BUG: memory leak
unreferenced object 0xffff…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-31714
|
2026-05-7 06:12 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
540
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: validate rec->used in journal-replay file record check
check_file_record() validates rec->total against the record size…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-31716
|
2026-05-7 06:10 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|