CVE-2026-53839

OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to send authentication material to untrusted endpoints.

Scoring

Severity
MEDIUM
CVSS base score
6.5
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS probability
0.27%
CWE
CWE-1023
Published
2026-06-12
Last modified
2026-07-14

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs