MEDIUM
OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL
Published May 6, 2026
4.9
MEDIUMCVSS 4.0
EPSS 0.44%
Description
OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pivot to untrusted second-hop targets. The webSocketDebuggerUrl response field is not properly validated, enabling attackers to redirect connections to arbitrary hosts and perform SSRF-style attacks.
Affected products
-
- Version 0StatusaffectedConstraints<2026.4.5
- Version 2026.4.5StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.4.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.4.5 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28164 Advisory
- https://github.com/advisories/GHSA-f7fh-qg34-x2xh Advisory
- https://github.com/openclaw/openclaw/commit/bc356cc8c2beaa747c71dd86cceab8f804699665 patch
- https://github.com/openclaw/openclaw/pull/60469
- https://github.com/openclaw/openclaw/security/advisories/GHSA-f7fh-qg34-x2xh vendor-advisoryMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-43576
- https://www.vulncheck.com/advisories/openclaw-second-hop-ssrf-via-cdp-json-version-websocket-url third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28164 | Advisory | |
| https://github.com/advisories/GHSA-f7fh-qg34-x2xh | Advisory | |
| https://github.com/openclaw/openclaw/commit/bc356cc8c2beaa747c71dd86cceab8f804699665 | patch | |
| https://github.com/openclaw/openclaw/pull/60469 | ||
| https://github.com/openclaw/openclaw/security/advisories/GHSA-f7fh-qg34-x2xh | vendor-advisoryMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-43576 | ||
| https://www.vulncheck.com/advisories/openclaw-second-hop-ssrf-via-cdp-json-version-websocket-url | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 6, 2026
Updated May 7, 2026
Reserved May 1, 2026
Link CVE-2026-43576
CISA Vulnrichment
Updated May 7, 2026
ENISA EUVD
EUVD-2026-28164 GHSA-F7FH-QG34-X2XH Assigner VulnCheck
Published May 6, 2026
Updated May 7, 2026
Exploited since n/a
Link EUVD-2026-28164