2026-05-06
2026-05-06 20:16Z
HIGH

CVE-2026-43585 — OpenClaw: Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43585

OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use rotated-out bearer tokens for unauthorized gateway access. CVSSv3.1 8.1 (HIGH)

CWECWE 672VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-06
2026-05-06 20:16Z
HIGH

CVE-2026-43584 — OpenClaw: before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43584

OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment policy that allows operator-supplied overrides of high-risk interpreter startup variables including VIMINIT, EXINIT, LUA_INIT, and HOSTALIASES. Attackers can exploit this by manipulating these environment variables to influence downstream execution behavior or network connectivity. CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 20:16Z
CRIT

CVE-2026-43581 — OpenClaw: before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43581

OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools protocol outside intended local sandbox boundaries by exploiting the overly broad binding configuration. CVSSv3.1 9.6 (CRITICAL)

CWECWE 1188VNDOpenclawTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-06
2026-05-06 20:16Z
CRIT

CVE-2026-43578 — OpenClaw: versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43578

OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can exploit this by providing untrusted completion content to leave a run in a more privileged context than intended. CVSSv3.1 9.1 (CRITICAL)

CWECWE 184VNDOpenclawTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-06
2026-05-06 20:16Z
CRIT

CVE-2026-43575 — OpenClaw: versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43575

OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge authentication to gain unauthorized access to the interactive browser session. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDOpenclawTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-06
2026-05-06 20:16Z
HIGH

CVE-2026-40076 — Openmrs Openmrs: In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module upload endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40076

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module upload endpoint at POST `/openmrs/ws/rest/v1/module` is vulnerable to a Zip Slip path traversal attack. During automatic extraction of uploaded .omod archives in `WebModuleUtil.startModule()`, ZIP entries under web/module/ are checked only to see whether the full entry path starts with `..,` and the remaining path is then concate CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDOpenmrsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-8018 — Google Chrome: Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8018

Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Low) CVSSv3.1 8.1 (HIGH)

VNDGoogleVNDDevtoolsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-8016 — Google Chrome: Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8016

Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-8002 — Google Chrome: Use after free in Audio in Google Chrome on Mac prior to 148.0.7778.96 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8002

Use after free in Audio in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-8001 — Google Chrome: Use After Free in Printing in Google Chrome on Linux, Mac, ChromeOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8001

Use After Free in Printing in Google Chrome on Linux, Mac, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.3 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-8000 — Google Chrome: Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8000

Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 20VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7995 — Google Chrome: Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7995

Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 125VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7992 — Google Chrome: Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7992

Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 20VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7991 — Google Chrome: Use after free in UI in Google Chrome prior to 148.0.7778.96 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7991

Use after free in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7988 — Google Chrome: Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7988

Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDGoogleVNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7987 — Google Chrome: Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7987

Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7985 — Google Chrome: Use after free in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7985

Use after free in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7984 — Google Chrome: Use after free in ReadingMode in Google Chrome prior to 148.0.7778.96 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7984

Use after free in ReadingMode in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7981 — Google Chrome: Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7981

Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 125VNDGoogleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7980 — Google Chrome: Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7980

Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7978 — Google Chrome: Inappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7978

Inappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 693VNDGoogleVNDInappropriateTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7975 — Google Chrome: Use after free in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7975

Use after free in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7974 — Google Chrome: Use after free in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7974

Use after free in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7973 — Google Chrome: Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7973

Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 472VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 19:16Z
HIGH

CVE-2026-7970 — Google Chrome: Use after free in TopChrome in Google Chrome prior to 148.0.7778.96 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7970

Use after free in TopChrome in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.3
CVSS v3.1
92
Edit Score