Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Raax

#18664of 53,624
14.4Total CVSS
Vulnerabilities · 2
High
2
PT-2026-31472
7.4
2026-04-08
Openclaw · Openclaw · CVE-2026-40037
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.8 Description OpenClaw contains a request body replay vulnerability in the `fetchWithSsrFGuard` function that allows unsafe request bodies to be resent across cross-origin redirects. This could allow attackers to exfiltrate sensitive request data or headers to unintended origins. Recommendations Update OpenClaw to version 2026.4.8 or later.
PT-2026-30235
7.0
2026-04-03
Openclaw · Openclaw · CVE-2026-34511
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.2 Description The application reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. An attacker capturing the redirect URL can obtain both the authorization code and PKCE verifier, defeating PKCE protection and enabling token redemption. Recommendations Update to version 2026.4.2 or later.