Home

Description

A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the function validateRegex of the file claw-orchestrator/src/embedded-server.ts of the component Session Grep Endpoint. The manipulation of the argument body.pattern leads to inefficient regular expression complexity. The attack may be initiated remotely. Upgrading to version 3.7.1 is sufficient to resolve this issue. The identifier of the patch is 3f970a974c65a94555c25af9f2796f11315e4584. It is recommended to upgrade the affected component.

PUBLISHED Reserved 2026-05-31 | Published 2026-06-01 | Updated 2026-06-02 | Assigner VulDB




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C
MEDIUM: 4.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C
4.0AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:OF/RC:C

Problem types

Inefficient Regular Expression Complexity

Resource Consumption

Product status

3.0
affected

3.1
affected

3.2
affected

3.3
affected

3.4
affected

3.5
affected

3.6
affected

3.7.0
affected

3.7.1
unaffected

Timeline

2026-05-31:Advisory disclosed
2026-05-31:VulDB entry created
2026-05-31:VulDB entry last update

Credits

ybdesire (VulDB User) reporter

References

github.com/Enderfga/claw-orchestrator/issues/64 exploit

vuldb.com/vuln/367584 (VDB-367584 | Enderfga claw-orchestrator Session Grep Endpoint embedded-server.ts validateRegex redos) vdb-entry technical-description

vuldb.com/vuln/367584/cti (VDB-367584 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/cve/CVE-2026-10291 (CVE-2026-10291 | CVE Analysis and Report) third-party-advisory

vuldb.com/submit/826222 (Submit #826222 | Enderfga claw-orchestrator v2.7.0-v3.7.0 Inefficient Regular Expression Complexity) third-party-advisory

github.com/Enderfga/claw-orchestrator/issues/64 issue-tracking

github.com/Enderfga/claw-orchestrator/issues/64 issue-tracking

github.com/...ommit/3f970a974c65a94555c25af9f2796f11315e4584 patch

github.com/Enderfga/claw-orchestrator/releases/tag/v3.7.1 patch

github.com/Enderfga/claw-orchestrator/ product

cve.org (CVE-2026-10291)

nvd.nist.gov (CVE-2026-10291)

Download JSON