Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 3 April 2026
RSS122 vulnerabilities published on 3 April 2026
Severity:
Azure SRE Agent: Unauthorized Access to Network Data
CVE-2026-32173
An attacker can exploit a weakness in the Azure SRE Agent to access sensitive information sent over a network if they don't have permission to do so. This could lead to the exposure of confidential da...
8.6
Electron apps: Video frame transfer via contextBridge can give attackers control
GHSA-jfqg-hf23-qpw2
CVE-2026-34780
Electron apps that share video data between browser and Node.js environments are at risk of being compromised by an attacker who can inject malicious code. To fix, avoid sharing video frames directly ...
8.4
Wisp Server Memory or Disk Overflow via Large Multipart Form Submissions
CVE-2026-32145
GHSA-8645-p2v4-73r2
An attacker can cause a Wisp server to run out of memory or disk space by sending a large multipart form submission. This can happen if an attacker sends a big file or a lot of small files in a single...
8.3
OpenClaw: Credentials Leaked If Onboarding Not Fully Completed
GHSA-9f4w-67g7-mqwv
A bug in OpenClaw's onboarding process allows an attacker who discovers an endpoint to continue accessing it even after it's been reported as untrusted. This can lead to unauthorized access to gateway...
8.3
OpenClaw Media Download Exposes Authorization Headers in Redirects
GHSA-68v4-hmwv-f43h
A security issue in OpenClaw version 2026.3.28 and earlier allows attackers to steal sensitive information when a user downloads media from a different website. This is a medium-risk vulnerability tha...
8.3
Auth0 Symfony SDK: Weak Cookie Encryption Allows Session Hijacking
GHSA-ghc5-95c2-vwcv
If you're using the Auth0 Symfony SDK between 5.0.0 and 5.7.0, an attacker could potentially guess your session cookies, allowing them to access your users' accounts. To fix this, update the Auth0 Sym...
8.2
Auth0 WordPress Plugin Cookie Encryption Weakness Exposes Session Hijacking Risk
GHSA-vfpx-q664-h93m
If you're using the Auth0 WordPress Plugin and the Auth0 PHP SDK, you may be vulnerable to hackers guessing your encrypted cookies. This could let them pretend to be your users. To fix this, update th...
8.2
Auth0 WordPress Plugin Uses Weak Cookie Encryption
GHSA-vfpx-q664-h93m
The Auth0 WordPress Plugin has a security weakness that could allow attackers to access user sessions. If you're using the plugin, you should update to the latest version to protect your users' sessio...
8.2
Auth0 Laravel SDK Cookie Encryption is Not Secure
GHSA-fmg6-246m-9g2v
If you use the Auth0 Laravel SDK, you may be at risk of attackers guessing your user session cookies. This is because the encryption used is not strong enough. To fix this, update the Auth0 Laravel SD...
8.2
Auth0 Laravel Auth0 SDK Uses Weak Cookie Encryption
GHSA-fmg6-246m-9g2v
If you use the Auth0 Laravel SDK in your PHP application, a weakness in the encryption of session cookies could allow hackers to guess the encryption key and impersonate users. To fix this, update the...
8.2
OpenClaw: LLM Agent Can Disable Exec Approval without User Consent
GHSA-v3qc-wrwx-j3pw
A security issue was found in OpenClaw, a library used by developers. A malicious agent could bypass the need for user approval to execute certain actions, potentially leading to unauthorized changes....
8.2
Telegram Migration in OpenClaw Allows Unauthorized Access to Some Accounts
GHSA-f693-58pc-2gfr
A recent update to OpenClaw, a tool for migrating Telegram accounts, has a security issue that could allow unauthorized access to some accounts. This is a low-level risk, but it's still important to u...
8.1
Electron: Using child windows with offscreen rendering can crash apps
GHSA-532v-xpq5-8h95
CVE-2026-34774
If you're using Electron to create apps with child windows and also render content offscreen, be aware that this setup can cause your app to crash or become unstable. To fix this, make sure to close c...
8.1
macOS OpenClaw App Allows Hackers to Steal Credentials
GHSA-q9w8-cf67-r238
A vulnerability in the OpenClaw app on macOS allows hackers to impersonate a trusted DNS server and steal sensitive user credentials. This can happen if the attacker is on the same network as the user...
7.8
Telegram Audio Transcription Allows Unauthorized Access to Resources
GHSA-m6fx-m8hc-572m
A security issue in OpenClaw allows unauthorized users to consume resources on Telegram groups, potentially leading to increased costs. This issue is present in versions of OpenClaw up to 2026.3.28. T...
7.8
OpenClaw Voice Call: Large WebSocket Frames Cause Resource Consumption
GHSA-2w79-r9g8-wmcr
If you're using a version of OpenClaw older than 2026.3.31, a hacker could send a specially crafted WebSocket message that consumes your system's resources, potentially causing it to slow down or cras...
7.8
OpenClaw Discord Audio Processing Exposes User Data Before Authorization
GHSA-hhff-fj5f-qg48
The OpenClaw software processes Discord audio before checking if the user is authorized, potentially exposing sensitive information. This could happen to anyone using an outdated version of OpenClaw. ...
7.8
Electron: Malicious Code Can Bypass Security Settings
GHSA-9wfr-w7mm-pc7f
CVE-2026-34769
If you use Electron to build desktop apps, be careful when using user input to configure your app's settings. An attacker could trick your app into disabling security features by injecting malicious c...
7.8
OpenClaw: Unpaired Device Can Access Host Privileges
GHSA-xj9w-5r6q-x6v4
An unsecured device can access sensitive host commands, potentially allowing an attacker to take control of the host system. This vulnerability affects devices paired with OpenClaw version 2026.3.28 o...
7.7
Discord Slash Commands Allow Unauthorized Group DM Access
GHSA-rvvf-6vh3-9j43
Discord's built-in slash commands can bypass channel restrictions, allowing authorized users to access restricted groups. This could potentially lead to unwanted messages or spam in those groups. Upda...
7.6
OpenClaw Node Browser Proxy Allows Bypass of Access Controls
GHSA-h5hg-h7rr-gpf3
A security issue in OpenClaw's node browser proxy allows an attacker to bypass access controls and gain unauthorized access to profiles. This means that sensitive data may be exposed if you're using a...
7.6
Ech0 allows unauthorized access to internal sites through link previews
GHSA-wc4h-2348-jc3p
CVE-2026-35036
The Ech0 server can be tricked into visiting any website, including internal sites, without user authentication. This happens when a user submits a malicious URL for a link preview. To fix this, updat...
7.5
Go JOSE Panics When Decrypting Certain JWE Objects
GHSA-78h2-9frx-2jm8
CVE-2026-34986
Go JOSE may crash when decrypting certain encrypted files, potentially causing a denial of service. This happens when it tries to decrypt a file with an empty encryption key. To avoid this, ensure tha...
7.5
Electron: Apps may crash when handling fullscreen or pointer-lock requests
GHSA-8337-3p73-46f4
CVE-2026-34771
Some Electron apps that ask users for permission to use their computer in fullscreen, pointer-lock, or keyboard-lock mode may crash or become unstable if a user navigates away or closes the window whi...
7.5
Sudo: Privilege Escalation from Setuid/setgid/setgroups Failure
CVE-2026-35535
The Sudo software has a security issue where certain errors during user privilege changes can lead to unauthorized access. This affects users who rely on Sudo for secure access to system features. To ...
7.4