CSSA Exclusive Early Warning10.0 Critical
Twisted HTTP request smuggling leading to access control bypass and cache poisoning
This flaw stems from incomplete validation of header field values in the HTTP parsing module: it does not strictly follow RFC requirements to reject bare carriage returns and line feeds, relying solely on the CRLF combination for message delimitation. An attacker can send crafted malicious HTTP requests over the network and exploit parsing differences in line terminator handling between the front-end proxy and the backend service, causing the two to disagree on message boundaries and enabling request smuggling. Affected environments face failure of upstream access control policies, abnormal connection pool state, tampering with response data and poisoning of shared caches.
Component
Twisted is an asynchronous network programming framework built on an event-driven architecture. Its core implements high-concurrency I/O multiplexing…
Type
HTTP Request/Response Smuggling (CWE-444)
Repo
Remediation- It is recommended to introduce strict HTTP message format validation at the middleware or application layer, filter all illegal control characters completely, unify front-end and backend parsing logic to eliminate semantic ambiguity, enable standardized protocol compliance checking, and keep the underlying communication library updated to a secure baseline version.
CVE-2026-66803CVSS 10.0 Critical2026-07-31
Azure Cosmos DB Improper Access Control Leading to Remote Code Execution
In Azure Cosmos DB, a defect in the access control mechanism (CWE-284) allows an unauthorized attacker to execute code over the network. The vulnerability lets an attacker trigger remote code execution without authentication, seriously threatening the confidentiality, integrity and availability of the system. Azure Cosmos DB contains a security flaw under certain network request scenarios that an attacker can trigger with a crafted request, leading to remote code execution or service disruption. The vulnerability affects all Azure Cosmos DB instances without additional protective measures. An attacker only needs network connectivity to launch the attack, requiring no user interaction and allowing remote control.
Component
Azure Cosmos DB is Microsoft's globally distributed multi-model database service, supporting document, key-value, graph and column-family data models.
Risks
- From standard user to administrator: If the victim runs the related service with administrative privileges, the attacker gains the same privileges
- Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: The attack is launched directly over the network; the attacker triggers the vulnerability without luring the user into any interaction
Source
Remediation- Monitor logs for anomalous network access behavior
- Enforce strict access control policies on the runtime environment
- Block network requests from untrusted sources
CVE-2026-66418CVSS 9.3 Critical2026-07-31
OpenClaw Dashboard Stored Cross-Site Scripting Leading to Administrator Session Hijacking and Configuration Tampering
In OpenClaw Dashboard v3.0.0, the audit log module has insufficient input validation and output encoding, resulting in stored cross-site scripting (CWE-79). An attacker can inject arbitrary HTML and script payloads into the audit log by submitting a crafted username in a failed login POST request. When an administrator opens the notification panel, unescaped log entries are rendered through innerHTML, and a permissive Content Security Policy allows inline event handlers, causing the malicious payload to execute in the administrator's session. The vulnerability allows an unauthenticated remote attacker to steal administrator session tokens and interact with authenticated endpoints including agent instruction file editing and configuration changes. It affects all unpatched OpenClaw Dashboard v3.0.0 users. An attacker only needs to induce an administrator to view the notification panel; user interaction is required but the impact is severe.
Component
OpenClaw Dashboard is a web dashboard for managing and monitoring OpenClaw systems, providing audit log viewing, configuration management and agent instruction editing.
Risks
- From standard user to administrator: An attacker can inject malicious code without authentication, and gains administrator privileges the moment an administrator views the log
- Complete system control: An attacker can execute arbitrary JavaScript in the administrator session, modify agent instruction files, change system configuration or steal sensitive data
- User interaction required: The attacker must induce an administrator to open the notification panel, which can be achieved through phishing emails or malicious links
Source
Remediation- Apply strict HTML entity encoding and output escaping to user input in audit logs
- Configure a strict Content Security Policy that prohibits inline script execution
CVE-2026-59310CVSS 9.8 Critical2026-07-30
VMware vCenter Syslog Directory Traversal Leading to Remote Code Execution
In VMware vCenter, improper path restriction in the Syslog server module results in a directory traversal (CWE-22) security flaw. An attacker with network access to vCenter may exploit this to execute arbitrary code. VMware vCenter contains a path traversal vulnerability when the Syslog service processes requests, which an attacker can trigger with a crafted request, leading to remote code execution or complete system control. The vulnerability affects all unpatched VMware vCenter deployments. An attacker needs only network access to exploit it, requiring no user interaction and allowing remote control.
Component
VMware vCenter is VMware's virtualization infrastructure management platform, used to centrally manage hosts, virtual machines and related services in a vSphere environment.
Risks
- Complete system control: An attacker can execute arbitrary code on the vCenter server and thereby take full control of the virtualization infrastructure
- High privilege escalation: Because vCenter typically runs with elevated privileges, successful exploitation may result in takeover of the entire virtualization cluster
- No user interaction required: The attacker does not need to lure a user into clicking a link or opening a file; sending a malicious request over the network is sufficient
Source
Remediation- Restrict network access to the vCenter Syslog port and allow connections only from trusted log collectors
- Monitor Syslog service access logs for anomalies to detect potential directory traversal attempts
Package Poisoning2026-07-31
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
d1128ffac25e89f7d931e7f96c5770cc
Package Poisoning2026-07-31
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
1990275a3458a7f4c2df7aedfe27a4b7
Package Poisoning2026-07-31
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
1430fc6243877f0ef52e7476c11438a1
Package Poisoning2026-07-31
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
324fb38f2805fb495e2ae88a21e9f8af
Package Poisoning2026-07-31
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
c899927ed0274fdbadd4a6a783883f2c
Package Poisoning2026-07-31
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
451d620d44d4fd0dadde0b6f63e838b2
Package Poisoning2026-07-31
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
38a56c1a703de5ff0f675d4520d645dc
Package Poisoning2026-07-31
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
9f8d2892589db398f9530824c3475e1d
Package Poisoning2026-07-31
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
6b0e027759bc53e4e79d0530532d01a9
Package Poisoning2026-07-31
@ flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
7b4e6a5ea0345b6a4dfa4212f8dd54be