CVE-2026-33580
OpenClaw's Nextcloud Talk webhook missing rate limiting on shared secret authentication
描述
## Summary Nextcloud Talk webhook signature failures were not throttled even though the integration relies on an operator-configured shared secret that may be weak. ## Impact An attacker who could reach the webhook endpoint could brute-force weak secrets online and then forge inbound webhook events. ## Affected Component `extensions/nextcloud-talk/src/monitor.ts` ## Fixed Versions - Affected: `<= 2026.3.24` - Patched: `>= 2026.3.28` - Latest stable `2026.3.28` contains the fix. ## Fix Fixed by commit `e403decb6e` (`nextcloud-talk: throttle repeated webhook auth failures`). OpenClaw thanks @AntAISecurityLab for reporting.
如何修補 CVE-2026-33580
要修補 CVE-2026-33580,請將受影響套件升級到下列已修補版本。
- —升級至 2026.3.28 或更新版本
CVE-2026-33580 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2026.3.28