Количество 2
Количество 2
CVE-2026-32019
OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-reserved ranges to bypass SSRF policy checks. Attackers with network reachability to special-use IPv4 ranges can exploit web_fetch functionality to access blocked addresses such as 198.18.0.0/15 and other non-global ranges.
GHSA-4rqq-w8v4-7p47
OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guard
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-32019 OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-reserved ranges to bypass SSRF policy checks. Attackers with network reachability to special-use IPv4 ranges can exploit web_fetch functionality to access blocked addresses such as 198.18.0.0/15 and other non-global ranges. | CVSS3: 7.4 | 0% Низкий | 6 месяцев назад | |
GHSA-4rqq-w8v4-7p47 OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guard | CVSS3: 5.3 | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу