DNS Rebinding Vulnerability in OpenClaw Gateway Application by Synology
CVE-2026-100555

7.1HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100555?

The OpenClaw gateway application, when operating on versions between 2026.7.1 and 2026.8.1, has a vulnerability regarding DNS pinning during attachment delivery in Synology Chat. The application validates only a single DNS result for file URLs, which can lead to unsafe hostname resolutions. This flaw allows an attacker to exploit DNS rebinding, potentially making the Synology NAS fetch private resources or content from restricted destinations. The impact of this vulnerability is highly dependent on the network configuration and the behavior of DNS resolvers. For enhanced security, users are advised to update to version 2026.8.1 or disable remote attachment forwarding in Synology Chat.

Affected Version(s)

OpenClaw 2026.7.1 < 2026.8.1

OpenClaw 2026.8.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.