CVE-2026-90712
A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.32%
- CWE
- CWE-404
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- Gitlawb openclaude
- Gitlawb openclaude
- Gitlawb openclaude
- Gitlawb openclaude
- Gitlawb openclaude
- Gitlawb openclaude
- Gitlawb openclaude
- Gitlawb openclaude
Weakness type
Related vulnerabilities
- CVE-2026-29771 — Netmaker: Denial of Service via Server Shutdown Endpoint
- CVE-2026-1876 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series Ethernet module
- CVE-2026-41869 — Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)
- CVE-2026-1875 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module
- CVE-2026-11317 — Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of Service Via CIP
- CVE-2026-10069 — Shibby Tomato miniupnpd resource consumption
- CVE-2026-45174 — Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initialization
- CVE-2026-4531 — Free5GC AMF handler.go HandleRegistrationComplete denial of service