Junglewise Threat Intelligence

CVE-2026-32029: OpenClaw improper X-Forwarded-For parsing allows client IP spoofing

CVE-2026-32029 · Severity: low · CVSS 3.1 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a gateway component that routes client requests through trusted proxies. The vulnerability allows attackers to spoof client IP addresses by injecting malicious values in the X-Forwarded-For header when proxies append rather than overwrite header values. An attacker could bypass IP-based security controls such as rate limiting on authentication or geographic access restrictions.

Technical details

OpenClaw's gateway component incorrectly uses the left-most value from the X-Forwarded-For HTTP header when processing requests from configured trusted proxies. The vulnerability (CWE-345: Insufficient Verification of Data Authenticity, CWE-807: Reliance on Untrusted Inputs in a Security Decision) occurs in non-standard proxy configurations where intermediate proxies append to or preserve inbound forwarding headers instead of overwriting them. An unauthenticated attacker on the network can inject arbitrary IP addresses into the X-Forwarded-For header to spoof their client IP, affecting security-sensitive decisions such as authentication rate-limit identity and local/private IP classification. The issue was patched in version 2026.2.21 through changes to the gateway's X-Forwarded-For parsing logic (commits 07039dc and 8877bfd). The vulnerability only affects deployments using non-recommended proxy forwarding behavior; standard configurations that overwrite headers are unaffected.

Affected products

  • OpenClaw openclaw <= 2026.2.19-2

Timeline

  • 2026-03-03: disclosed: Advisory published by GitHub
  • 2026-02-21: patched: Advisory marked published on Feb 21, 2026; patched version 2026.2.21 planned
  • 2026-03-19: other: NVD published CVE-2026-32029

References

Related threats