Medium severity6.5NVD Advisory· Published Jun 12, 2026· Updated Jun 16, 2026
CVE-2026-53839
CVE-2026-53839
Description
OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to send authentication material to untrusted endpoints.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-77q5-rr5v-x43qnvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-hostname-prefix-matching-bypass-in-trusted-retry-endpoint-validationnvdThird Party Advisory
News mentions
1- OpenClaw: 25 CVEs Disclosed in Largest Security Batch, Including Code Execution and Critical Auth BypassVypr Intelligence · Jun 12, 2026