Openclaw Openclaw — CVE-2026-32913 (Critical)
Critical vendor advisory
CVE-2026-32913
Summary
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 9.3) in Openclaw Openclaw. Patch or mitigate promptly.
Operator check
Review CVE-2026-32913 in your asset inventory. Apply patches per vendor guidance and verify Openclaw is not exposed. CVSS score: 9.3.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.