Description
OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. Attackers can exploit this by crafting URLs targeting internal or non-routable IPv6 addresses to bypass SSRF protections.
Problem types
CWE-184: Incomplete List of Disallowed Inputs
Product status
Any version before 2026.3.28
2026.3.28 (semver)
Credits
Nicky (@nicky-cc) of Tencent zhuque Lab
References
github.com/...enclaw/security/advisories/GHSA-g86v-f9qv-rh6m (GitHub Security Advisory (GHSA-g86v-f9qv-rh6m))
www.vulncheck.com/...uard-bypass-via-ipv6-special-use-ranges (VulnCheck Advisory: OpenClaw < 2026.3.28 - SSRF Guard Bypass via IPv6 Special-Use Ranges)