Количество 2
Количество 2
CVE-2026-35623
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can repeatedly submit incorrect password guesses to the webhook endpoint to compromise authentication and gain unauthorized access.
GHSA-xq8g-hgh6-87hv
OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35623 OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can repeatedly submit incorrect password guesses to the webhook endpoint to compromise authentication and gain unauthorized access. | CVSS3: 4.8 | 0% Низкий | 4 месяца назад | |
GHSA-xq8g-hgh6-87hv OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing | CVSS3: 4.8 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу