OpenClaw's security feed produced another CVE alert this week, and if you scan past the header, the interesting part is not the vulnerability. It is the architecture lesson hiding inside the patch. CVE-2026-35629, scored CVSS v3.1 7.4 (5.3 v4) by VulnCheck, describes a server-side request