Server-Side Request Forgery (SSRF) in OpenClaw - #VU125083
Published: April 7, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass SSRF preflight checks.
The vulnerability exists due to improper restriction of destination addresses in the SSRF IP classifier when processing IPv6 multicast literals. A remote attacker can supply a URL containing an IPv6 multicast literal to bypass SSRF preflight checks.
OpenClaw's network fetch and navigation paths are constrained to HTTP/HTTPS.