Executive brief
OpenClaw's web fetch functionality includes a security filter designed to block Server-Side Request Forgery (SSRF) attacks by preventing connections to reserved IPv4 addresses. However, the filter was incomplete and missed several RFC-defined special-use IP ranges, allowing attackers to bypass the protection and access internal network resources that should have been blocked.
Technical details
The isPrivateIpv4() function in OpenClaw's bundled SSRF guard code used an overly narrow allowlist of IPv4 private ranges, omitting multiple RFC-defined special-use and non-global ranges including benchmarking addresses (198.18.0.0/15), TEST-NET ranges, multicast blocks, and reserved ranges. This allowed HTTP requests to special-use IP addresses like http://198.18.0.1/ to bypass SSRF validation in the web_fetch functionality. The vulnerability requires network reachability to the relevant special-use ranges and a request path that invokes the web_fetch URL fetching mechanism. The fix consolidates IPv4 classification logic into a single CIDR policy table using ipaddr.js library and applies standardized checks across gateway, browser, and tailnet paths to prevent classifier drift.
Affected products
- OpenClaw openclaw <= 2026.2.21-2
Timeline
- 2026-02-23: disclosed
- 2026-02-22: patched: Patched version 2026.2.22 planned
- 2026-03-04: advisory
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-4rqq-w8v4-7p47
- https://github.com/openclaw/openclaw/commit/333fbb86347998526dd514290adfd5f727caa6d9
- https://github.com/openclaw/openclaw/commit/44dfbd23df453e51b71ef79a148c28c53e89168c
- https://github.com/openclaw/openclaw/commit/71bd15bb4294d3d1b54386064d69cd0f5f731bd8
- https://github.com/openclaw/openclaw/commit/f14ebd743cfc73f667fae80af70043d0ab1f88bd
- https://github.com/openclaw/openclaw