OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation
CVE-2026-53839
6MEDIUM
What is CVE-2026-53839?
OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to send authentication material to untrusted endpoints.
Affected Version(s)
OpenClaw 0 < 2026.5.7
OpenClaw 2026.5.7
