cve.
Everything we've published on cve across guides, agents, hardware reviews and glossary entries — 8 entries in total.
Guides (5)
- OpenClaw security crisis 2026: what you need to knowAI Agents · 2026-04-28
OpenClaw shipped a one-click RCE in January 2026. ~1000 public installations were running without auth. Here's what happened, what's exposed, and what to do.
- vLLM security CVEs 2026: auth bypass and trust_remote_code RCEAI Agents · 2026-07-06
vLLM shipped CVE-2026-48746 (auth bypass, CVSS 9.1) plus trust_remote_code RCEs CVE-2026-4944 and CVE-2026-5817. Upgrade to 0.22.1+ now and lock these settings.
- Vector database authorization CVEs: ChromaDB, Weaviate 2026AI Agents · 2026-07-06
ChromaDB (CVE-2026-45830 to -45833) and Weaviate (CVE-2026-59093) shipped multi-tenant authorization-bypass CVEs in 2026. The shared pattern, and the fix.
- MLflow authorization CVEs 2026: artifacts, traces, gateway leaksAI Agents · 2026-07-06
MLflow shipped three authorization and secrets CVEs in 2026 — CVE-2026-2651 (critical), CVE-2026-8147, and CVE-2026-4035. What each one breaks and how to patch.
- Ollama heap leak (CVE-2026-5757) and inference-server memory safetyAI Agents · 2026-07-06
Ollama CVE-2026-5757 leaks heap memory to unauthenticated callers; Triton's DALI backend (CVE-2026-24213/24214/24264) has integer-overflow and OOB bugs.
Agents (2)
- OpenClaw
The original viral self-hosted AI agent. Post-crisis 2026.4 line is genuinely safer; pre-2026.3 is genuinely dangerous.
- DeployHermes
First managed-Hermes-Agent service. $19/month for a hosted Hermes deployment with dashboard, SSO and CVE monitoring.
Glossary (1)
- CVE-2026-25253 — Critical 1-click remote code execution vulnerability in OpenClaw versions before 2026.2.10. CVSS 9.6.