CVE-2026-53859
Severity CVSS v4.0:
MEDIUM
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
16/06/2026
Last modified:
16/06/2026
Description
OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. Attackers can exploit inconsistent hostname checks to reach destinations that operators intended to block through hostname policies.
Impact
Base Score 4.0
6.00
Severity 4.0
MEDIUM
Base Score 3.x
6.50
Severity 3.x
MEDIUM



