DNS Rebinding Vulnerability in OpenClaw Agent Gateway by OpenClaw
CVE-2026-100567

8.9HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100567?

The OpenClaw agent gateway, available as the npm package 'openclaw', has a vulnerability that impacts versions from 2026.4.5 to below 2026.8.1. An improper DNS validation allows an attacker with control over a sanctioned Chrome DevTools Protocol (CDP) hostname to exploit a check-then-use flaw through DNS rebinding. This could result in the gateway connecting to restricted addresses such as loopback or private networks, potentially exposing sensitive services. Users are advised to upgrade to version 2026.8.1 or later, and to disable or restrict hostname-based CDP endpoints to mitigate risks.

Affected Version(s)

OpenClaw 2026.4.5 < 2026.8.1

OpenClaw 2026.8.1

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.