Description
OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For header processing when trustedProxies is configured, allowing attackers to spoof loopback hops. Remote attackers can inject forged forwarding headers to bypass canvas authentication and rate-limiting protections by masquerading as loopback clients.
Problem types
CWE-290: Authentication Bypass by Spoofing
Product status
Any version before 2026.3.22
2026.3.22 (semver)
Credits
lintsinghua
References
github.com/...enclaw/security/advisories/GHSA-844j-xrrq-wgh4 (GitHub Security Advisory (GHSA-844j-xrrq-wgh4))
github.com/...ommit/630f1479c44f78484dfa21bb407cbe6f171dac87 (Patch Commit #1)
github.com/...ommit/fc2d29ea926f47c428c556e92ec981441228d2a4 (Patch Commit #2)
www.vulncheck.com/...-canvas-authentication-and-rate-limiter (VulnCheck Advisory: OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter)