MEDIUM
OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter
Published Apr 10, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.55%
Description
OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For header processing when trustedProxies is configured, allowing attackers to spoof loopback hops. Remote attackers can inject forged forwarding headers to bypass canvas authentication and rate-limiting protections by masquerading as loopback clients.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.22
- Version 2026.3.22StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.22
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.22 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/advisories/GHSA-844j-xrrq-wgh4 Advisory
- https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 patch
- https://github.com/openclaw/openclaw/commit/fc2d29ea926f47c428c556e92ec981441228d2a4 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-844j-xrrq-wgh4 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-35656
- https://www.vulncheck.com/advisories/openclaw-xff-loopback-spoofing-bypass-in-canvas-authentication-and-rate-limiter third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-844j-xrrq-wgh4 | Advisory | |
| https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 | patch | |
| https://github.com/openclaw/openclaw/commit/fc2d29ea926f47c428c556e92ec981441228d2a4 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-844j-xrrq-wgh4 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-35656 | ||
| https://www.vulncheck.com/advisories/openclaw-xff-loopback-spoofing-bypass-in-canvas-authentication-and-rate-limiter | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 10, 2026
Updated Jun 23, 2026
Reserved Apr 4, 2026
Link CVE-2026-35656
CISA Vulnrichment
GHSA-844J-XRRQ-WGH4 Updated Apr 10, 2026