๐จ CVE-2026-54128
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
๐@cveNotify
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-56159
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-56168
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
๐@cveNotify
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-56173
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-47423
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5.
๐@cveNotify
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5.
๐@cveNotify
GitHub
release: 3.4.5 (#1382) ยท cure53/DOMPurify@011b0c7
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: - release: 3.4.5 (#1382) ยท cure53/DOMPurify@011b0c7
๐จ CVE-2026-49458
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.
๐@cveNotify
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.
๐@cveNotify
GitHub
release: 3.4.6 (#1394) ยท cure53/DOMPurify@bb7739e
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: - release: 3.4.6 (#1394) ยท cure53/DOMPurify@bb7739e
๐จ CVE-2026-49459
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.
๐@cveNotify
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.
๐@cveNotify
GitHub
release: 3.4.6 (#1394) ยท cure53/DOMPurify@bb7739e
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: - release: 3.4.6 (#1394) ยท cure53/DOMPurify@bb7739e
๐จ CVE-2026-35146
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.
๐@cveNotify
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL DFXServer - Customer Support
HCL DFXServer is affected by multiple security vulnerabilities.
๐จ CVE-2026-62202
OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging misconfigured input paths in the affected cron feature.
๐@cveNotify
OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging misconfigured input paths in the affected cron feature.
๐@cveNotify
GitHub
Isolated cron jobs could regain denied exec tools
### Summary
Isolated cron jobs could regain denied exec tools. In affected versions, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended...
Isolated cron jobs could regain denied exec tools. In affected versions, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended...
๐จ CVE-2026-62205
OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. The issue is fixed in 2026.6.6.
๐@cveNotify
OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. The issue is fixed in 2026.6.6.
๐@cveNotify
GitHub
MS Teams message actions could miss requester authorization
### Summary
MS Teams message actions could miss requester authorization. In affected versions, a lower-trust caller or configured input path could perform actions that should have required a stron...
MS Teams message actions could miss requester authorization. In affected versions, a lower-trust caller or configured input path could perform actions that should have required a stron...
๐จ CVE-2026-62209
OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check.
๐@cveNotify
OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check.
๐@cveNotify
GitHub
ClickClack agent-mode dispatch could ignore toolsAllow
### Summary
ClickClack agent-mode dispatch could ignore toolsAllow. In affected versions, a lower-trust caller or configured input path could perform actions that should have required a stronger a...
ClickClack agent-mode dispatch could ignore toolsAllow. In affected versions, a lower-trust caller or configured input path could perform actions that should have required a stronger a...
๐จ CVE-2026-62216
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path.
๐@cveNotify
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path.
๐@cveNotify
GitHub
QQBot media upload could reach untrusted remote URLs
### Summary
QQBot media upload could reach untrusted remote URLs. In affected versions, a lower-trust caller or configured input path could reach network destinations that should have been blocked...
QQBot media upload could reach untrusted remote URLs. In affected versions, a lower-trust caller or configured input path could reach network destinations that should have been blocked...
๐จ CVE-2026-62217
OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, allowing non-allowlisted senders to perform unauthorized operations.
๐@cveNotify
OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, allowing non-allowlisted senders to perform unauthorized operations.
๐@cveNotify
GitHub
QQBot exec approvals could allow non-allowlisted senders
### Summary
QQBot exec approvals could allow non-allowlisted senders. In affected versions, a lower-trust caller or configured input path could execute or persist actions beyond the caller's i...
QQBot exec approvals could allow non-allowlisted senders. In affected versions, a lower-trust caller or configured input path could execute or persist actions beyond the caller's i...
๐จ CVE-2026-62218
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths.
๐@cveNotify
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths.
๐@cveNotify
GitHub
device.pair.approve could bypass role-management checks
### Summary
device.pair.approve could bypass role-management checks. In affected versions, a lower-trust caller or configured input path could perform actions that should have required a stronger ...
device.pair.approve could bypass role-management checks. In affected versions, a lower-trust caller or configured input path could perform actions that should have required a stronger ...
๐จ CVE-2026-62219
OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger authorization or policy checks.
๐@cveNotify
OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger authorization or policy checks.
๐@cveNotify
GitHub
Hooks allowedAgentIds could be bypassed with blank agent IDs
### Summary
Hooks allowedAgentIds could be bypassed with blank agent IDs. In affected versions, a lower-trust caller or configured input path could perform actions that should have required a stro...
Hooks allowedAgentIds could be bypassed with blank agent IDs. In affected versions, a lower-trust caller or configured input path could perform actions that should have required a stro...
๐จ CVE-2026-62220
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce service availability.
๐@cveNotify
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce service availability.
๐@cveNotify
GitHub
WebSocket auth attempts could avoid non-browser rate limits
### Summary
WebSocket auth attempts could avoid non-browser rate limits. In affected versions, a lower-trust caller or configured input path could consume gateway resources and reduce availability...
WebSocket auth attempts could avoid non-browser rate limits. In affected versions, a lower-trust caller or configured input path could consume gateway resources and reduce availability...
๐จ CVE-2026-62221
OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.
๐@cveNotify
OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.
๐@cveNotify
GitHub
ClickClack allowFrom could allow non-allowlisted commands
### Summary
ClickClack allowFrom could allow non-allowlisted commands. In affected versions, a lower-trust caller or configured input path could execute or persist actions beyond the caller's ...
ClickClack allowFrom could allow non-allowlisted commands. In affected versions, a lower-trust caller or configured input path could execute or persist actions beyond the caller's ...
๐จ CVE-2026-62226
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks.
๐@cveNotify
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks.
๐@cveNotify
GitHub
Browser act route could miss current-tab URL checks
### Summary
Browser act route could miss current-tab URL checks. In affected versions, a lower-trust caller or configured input path could perform actions that should have required a stronger auth...
Browser act route could miss current-tab URL checks. In affected versions, a lower-trust caller or configured input path could perform actions that should have required a stronger auth...
๐จ CVE-2026-62227
OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach network destinations that should have been blocked.
๐@cveNotify
OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach network destinations that should have been blocked.
๐@cveNotify
GitHub
Browser snapshot routes could miss post-navigation SSRF checks
### Summary
Browser snapshot routes could miss post-navigation SSRF checks. In affected versions, a lower-trust caller or configured input path could reach network destinations that should have be...
Browser snapshot routes could miss post-navigation SSRF checks. In affected versions, a lower-trust caller or configured input path could reach network destinations that should have be...
๐จ CVE-2026-62228
OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions.
๐@cveNotify
OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions.
๐@cveNotify
GitHub
Node exec approvals could use different gateway and node environments
### Summary
Node exec approvals could use different gateway and node environments. In affected versions, a lower-trust caller or configured input path could execute or persist actions beyond the c...
Node exec approvals could use different gateway and node environments. In affected versions, a lower-trust caller or configured input path could execute or persist actions beyond the c...
๐จ CVE-2026-26080
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
๐@cveNotify
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
๐@cveNotify