PT-2026-99203 · Openclaw · Openclaw

CVE-2026-100567

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.9

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.4.5 through 2026.8.0
Description The Gateway validates a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw WebSocket and Playwright transports perform a subsequent, independent DNS resolution. This creates a check-then-use gap that allows an attacker controlling an approved CDP hostname or its DNS answers to use DNS rebinding—a technique used to bypass Same-Origin Policy by changing DNS records between requests—to force the Gateway to connect to loopback, private, link-local, cloud metadata, or other SSRF-policy-denied addresses. Server-Side Request Forgery (SSRF) is a vulnerability where an attacker induces a server-side application to make requests to an unintended location.
Recommendations Update to version 2026.8.1. Disable hostname-based remote CDP endpoints. Restrict remote CDP endpoints to trusted, stable infrastructure.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100567
GHSA-P3H6-V2H4-36Q2

Affected Products

Openclaw