VYPR
Medium severity6.5NVD Advisory· Published Jun 12, 2026· Updated Jun 16, 2026

CVE-2026-53839

CVE-2026-53839

Description

OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to send authentication material to untrusted endpoints.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • OpenClaw/Openclawinferred3 versions
    <2026.5.7+ 2 more
    • (no CPE)range: <2026.5.7
    • cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*range: <2026.5.7
    • (no CPE)range: <2026.5.7

Patches

Vulnerability mechanics

References

2

News mentions

1