OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation f
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| OpenClaw | OpenClaw Windows Node | 0 ~ 2026.7.1 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-101880 | 8.8 HIGH | OpenClaw Windows Node before 2026.7.1 Authorization Bypass |
| CVE-2026-101882 | 8.8 HIGH | OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set |
| CVE-2026-101884 | 7.5 HIGH | OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override |
| CVE-2026-101879 | 6.5 MEDIUM | OpenClaw Windows Node before 2026.7.1-3 Missing Authorization |
| CVE-2026-101883 | 5.4 MEDIUM | OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present |
暂无评论