Количество 2
Количество 2
CVE-2026-34503
OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection.
GHSA-2pr2-hcv6-7gwv
OpenClaw's device removal and token revocation do not terminate active WebSocket sessions
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-34503 OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection. | CVSS3: 8.1 | 0% Низкий | 4 месяца назад | |
GHSA-2pr2-hcv6-7gwv OpenClaw's device removal and token revocation do not terminate active WebSocket sessions | CVSS3: 7.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу