LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-32029

openclaw · openclaw

Published
CVSS5.3
Severitymedium
WeaknessCWE-345
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate from configured trusted proxies, allowing attackers to spoof client IP addresses. In proxy chains that append or preserve header values, attackers can inject malicious header content to influence security decisions including authentication rate-limiting and IP-based access controls.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32029

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32029.