Hostname Validation Vulnerability in OpenClaw Software
CVE-2026-53859

6MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-53859?

OpenClaw prior to version 2026.5.26 is susceptible to a hostname validation vulnerability that enables attackers to circumvent blocklist policies by utilizing trailing-dot notation within URLs. This issue allows malicious actors to exploit discrepancies in hostname checks, potentially redirecting users to destinations that administrators aimed to restrict. It's crucial for users to update to the latest version to mitigate these risks.

Affected Version(s)

OpenClaw 0 < 2026.5.26

OpenClaw 2026.5.26

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chinmohan Nayak (@nayakchinmohan)
.