2026 CVE Vulnerabilities

65,368 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40113HIGH8.1PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the ...
CVE-2026-40112MEDIUM6.1PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent ...
CVE-2026-40111HIGH8.8PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a us...
CVE-2026-39848MEDIUM5.4Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed ...
CVE-2026-35646MEDIUM6.5OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that...
CVE-2026-35645HIGH8.8OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSe...
CVE-2026-35644HIGH7.1OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scop...
CVE-2026-35642MEDIUM5.3OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireM...
CVE-2026-35640HIGH7.5OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated atta...
CVE-2026-35639HIGH8.8OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an...
CVE-2026-35638HIGH8.8OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated se...
CVE-2026-35637HIGH7.3OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite w...
CVE-2026-35636HIGH7.1OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status reso...
CVE-2026-35635MEDIUM6.5OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that al...
CVE-2026-35634MEDIUM5.1OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasReq...
CVE-2026-35633MEDIUM6.9OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that...
CVE-2026-35632HIGH7.8OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that u...
CVE-2026-35631HIGH7.1OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unautho...
CVE-2026-35629HIGH7.4OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail ...
CVE-2026-35628MEDIUM6.5OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows ...
CVE-2026-35627HIGH8.2OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforci...
CVE-2026-35626MEDIUM6.9OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling t...
CVE-2026-35625HIGH8.5OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-a...
CVE-2026-35624MEDIUM5.4OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room na...
CVE-2026-35623MEDIUM6.5OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now