Openclaw Openclaw — CVE-2026-32913 (Critical)

Date Mar 23, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Openclaw · Openclaw
CVE CVE-2026-32913
Critical vendor advisory CVE-2026-32913

Summary

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 9.3) in Openclaw Openclaw. Patch or mitigate promptly.

Operator check

Review CVE-2026-32913 in your asset inventory. Apply patches per vendor guidance and verify Openclaw is not exposed. CVSS score: 9.3.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.