GHSA-vqx6-6j84-2794Medium· 6.5▾ SunlitDuplicate Advisory: Hostname checks could treat trailing-dot hosts inconsistently
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-gxg4-2rrr-jhc7. This link is maintained to preserve external references.
OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. Attackers can exploit inconsistent hostname checks to reach destinations that operators intended to block through hostname policies.
openclaw <= 2026.5.22Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100576Medium· 5.4OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations
CVE-2026-100577Medium· 6.3OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations
CVE-2026-100574Medium· 5.9OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks
CVE-2026-100567High· 8.2OpenClaw is an agent gateway distributed as the npm package 'openclaw'
CVE-2026-100555High· 7.1OpenClaw is an npm-distributed gateway application
GHSA-c29c-2q9c-pc86HighOpenClaw: Slack allowFrom could bind to mutable display names