Junglewise Threat Intelligence

CVE-2026-35656: OpenClaw authentication bypass via X-Forwarded-For spoofing

CVE-2026-35656 · Severity: medium · CVSS 6.5 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a software package used for gateway and authentication services. A security flaw was found where the system could be tricked into misidentifying a user's true location or identity by using fake network headers. This could allow attackers to bypass security restrictions like rate limits or certain authentication checks, potentially leading to unauthorized access or service abuse.

Technical details

A vulnerability in OpenClaw's gateway component (specifically in src/gateway/net.ts) allows for authentication bypass by spoofing. When 'gateway.trustedProxies' is configured, the application fails to properly validate loopback hops in forwarding headers (such as X-Forwarded-For). An unauthenticated remote attacker can inject spoofed loopback addresses into these headers to be accepted as the trusted client origin. This misidentification weakens downstream security decisions in 'canvas auth' and 'gateway auth-rate-limit' paths. The issue is fixed in version 2026.3.22 by ensuring loopback forwarded hops are ignored during trusted-proxy client resolution.

Affected products

  • OpenClaw openclaw < 2026.3.22

Timeline

  • 2026-03-24: disclosed: Initial disclosure on GitHub
  • 2026-03-22: patched: Fix released in version 2026.3.22
  • 2026-03-26: advisory: GitHub Advisory published
  • 2026-04-10: other: NVD published CVE-2026-35656

References

Related threats