2026 CVE Vulnerabilities
49,144 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42424 | MEDIUM | 5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channe... |
| CVE-2026-42421 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared ga... |
| CVE-2026-42420 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing... |
| CVE-2026-41916 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure become... |
| CVE-2026-41915 | MEDIUM | 6.1 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host e... |
| CVE-2026-41913 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent ... |
| CVE-2026-41911 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local f... |
| CVE-2026-41910 | MEDIUM | 4.3 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An ... |
| CVE-2026-41408 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limi... |
| CVE-2026-41407 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use ea... |
| CVE-2026-41406 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restri... |
| CVE-2026-41403 | MEDIUM | 4 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRe... |
| CVE-2026-41402 | MEDIUM | 5.4 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authen... |
| CVE-2026-41398 | MEDIUM | 4.6 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic lo... |
| CVE-2026-41393 | MEDIUM | 4.8 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a wide-area discovery vulnerability allowing arbitrary tailnet peers to be accepted a... |
| CVE-2026-41391 | MEDIUM | 6.1 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execut... |
| CVE-2026-41388 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array s... |
| CVE-2026-41382 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers ... |
| CVE-2026-41381 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attac... |
| CVE-2026-41377 | MEDIUM | 5.1 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failure... |
| CVE-2026-41376 | MEDIUM | 6.5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling th... |
| CVE-2026-41374 | MEDIUM | 6.9 | 0.5% | Apr 28, 2026 | OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowin... |
| CVE-2026-41373 | MEDIUM | 6.1 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary en... |
| CVE-2026-24231 | MEDIUM | 6.3 | 0.1% | Apr 28, 2026 | NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could... |
| CVE-2026-24204 | MEDIUM | 6.5 | 0.4% | Apr 28, 2026 | NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now