在 OpenClaw 2026.9.5 及之前版本中发现了一个漏洞。该漏洞影响了 Canvas Host Route 组件中文件 的 函数。攻击者可通过远程执行特定操作导致拒绝服务(DoS)。该漏洞的利用代码已公开,可能被用于实际攻击。 修复建议中提到的 “streaming/size-limit”(流式处理/大小限制)功能并未实际发布——最新版本的 2026.9.5 仍通过 函数缓冲整个文件(参见 第 17 行和第 114 行),而与其并列的 WebSocket 路径则已将数据大小限制在 64KB。漏洞披露方已在
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | OpenClaw | 2026.9.0 |
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93962 | 8.3 HIGH | Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow |
| CVE-2026-94004 | 7.3 HIGH | DedeCMS mytag_js.php code injection |
| CVE-2026-94043 | 5.3 MEDIUM | Free5GC Gmm handler.go race condition |
| CVE-2026-93960 | 4.3 MEDIUM | Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication |
| CVE-2026-94030 | 3.1 LOW | SerenityOS LibGfx BMPLoader.cpp decode_bmp_pixel_data integer overflow |
No comments yet