Количество 2
Количество 2
CVE-2026-43585
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use rotated-out bearer tokens for unauthorized gateway access.
GHSA-xmxx-7p24-h892
OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-43585 OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use rotated-out bearer tokens for unauthorized gateway access. | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
GHSA-xmxx-7p24-h892 OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation | CVSS3: 8.1 | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу