DNS Rebinding Vulnerability in OpenClaw Gateway Application by Synology
CVE-2026-100555
7.1HIGH
What is CVE-2026-100555?
The OpenClaw gateway application, when operating on versions between 2026.7.1 and 2026.8.1, has a vulnerability regarding DNS pinning during attachment delivery in Synology Chat. The application validates only a single DNS result for file URLs, which can lead to unsafe hostname resolutions. This flaw allows an attacker to exploit DNS rebinding, potentially making the Synology NAS fetch private resources or content from restricted destinations. The impact of this vulnerability is highly dependent on the network configuration and the behavior of DNS resolvers. For enhanced security, users are advised to update to version 2026.8.1 or disable remote attachment forwarding in Synology Chat.
Affected Version(s)
OpenClaw 2026.7.1 < 2026.8.1
OpenClaw 2026.8.1
