PT-2026-99203 · Openclaw · Openclaw
CVE-2026-100567
·
Published
2026-09-26
·
Updated
2026-09-28
CVSS v4.0
8.9
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.4.5 through 2026.8.0
Description
The Gateway validates a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw WebSocket and Playwright transports perform a subsequent, independent DNS resolution. This creates a check-then-use gap that allows an attacker controlling an approved CDP hostname or its DNS answers to use DNS rebinding—a technique used to bypass Same-Origin Policy by changing DNS records between requests—to force the Gateway to connect to loopback, private, link-local, cloud metadata, or other SSRF-policy-denied addresses. Server-Side Request Forgery (SSRF) is a vulnerability where an attacker induces a server-side application to make requests to an unintended location.
Recommendations
Update to version 2026.8.1.
Disable hostname-based remote CDP endpoints.
Restrict remote CDP endpoints to trusted, stable infrastructure.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw