Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

SSRF via unrestricted gatewayUrl override in OpenClaw Gateway tool

IdentifiersCVE-2026-26322CWE-918· Server-Side Request Forgery (SSRF)

In OpenClaw prior to version 2026.2.14, the Gateway tool accepted a tool-supplied gatewayUrl and allowed some tool call paths to pass that value into the Gateway WebSocket client without sufficient validation or allowlisting. As a result, an authorized or otherwise capable tool caller could cause the OpenClaw host to initiate outbound WebSocket connections to attacker-specified endpoints instead of only approved gateway destinations. Reachable targets could include localhost services, private network addresses, and cloud metadata IPs. The issue is effectively a server-side request forgery condition in the WebSocket client path. The vendor states that version 2026.2.14 restricts tool-supplied gatewayUrl overrides to loopback on the configured gateway port or the configured gateway.remote.url, and rejects disallowed protocols, embedded credentials, query or hash components, and non-root paths.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an attacker or red teamer who can invoke affected tool paths to coerce the OpenClaw host into making outbound WebSocket connection attempts to arbitrary destinations. In the common case this produces connection attempts, errors, or timeouts from the OpenClaw host. Where the caller can observe responses or behavioral differences, the flaw can be used for limited internal network reachability probing against localhost, RFC1918/private addresses, or cloud metadata services. If the destination is reachable and speaks WebSocket, additional interaction with that service may be possible, potentially expanding access to internal-only services or sensitive metadata endpoints.

Mitigation

If you can’t patch tonight, do this now.

Until patched, restrict who can invoke tool calls that accept gatewayUrl overrides, directly or indirectly. Ensure these tool paths are available only to authenticated and trusted operators or trusted automation. If such tool calls are exposed to non-operators, disable the override capability or enforce a strict allowlist of permitted gateway endpoints. At the network layer, block or tightly control egress from the OpenClaw host to sensitive internal destinations, including localhost, RFC1918 ranges, link-local addresses, and cloud metadata IPs.

Remediation

Patch, then assume compromise.

Upgrade OpenClaw to version 2026.2.14 or later. The fix restricts gatewayUrl overrides to loopback on the configured gateway port or the configured gateway.remote.url, and rejects unsupported protocols, credentials, query/hash components, and non-root paths. The referenced fix commit is c5406e1d2434be2ef6eb4d26d8f1798d718713f4.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
OpenclawOpenclawapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity3

Community discussion across Reddit, Mastodon, and other social sources.