CVE-2026-10617

Source
https://cve.org/CVERecord?id=CVE-2026-10617
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10617.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-10617
Published
2026-06-02T19:00:12Z
Modified
2026-08-29T03:45:15Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
nextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authentication
Details

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhook Verification Handler. The manipulation leads to missing authentication. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-287",
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10617.json"
}
References

Affected packages

Git / github.com/nextlevelbuilder/goclaw

Affected ranges

Type
GIT
Repo
https://github.com/nextlevelbuilder/goclaw
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.11.0"
        },
        {
            "last_affected": "3.11.0"
        },
        {
            "introduced": "3.11.1"
        },
        {
            "last_affected": "3.11.1"
        },
        {
            "introduced": "3.11.2"
        },
        {
            "last_affected": "3.11.2"
        },
        {
            "introduced": "3.11.3"
        },
        {
            "last_affected": "3.11.3"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

3.*
3.11.0
3.11.1
3.11.2
3.11.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10617.json"