Description
OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to send authentication material to untrusted endpoints.
Problem types
Incomplete Comparison with Missing Factors
Product status
Any version before 2026.5.7
2026.5.7 (semver)
Credits
ccy41928-del
References
github.com/...enclaw/security/advisories/GHSA-77q5-rr5v-x43q (GitHub Security Advisory (GHSA-77q5-rr5v-x43q))
www.vulncheck.com/...ss-in-trusted-retry-endpoint-validation (VulnCheck Advisory: OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation)