CVE-2026-32019: OpenClaw < 2026.2.22 - Incomplete IPv4 Special-Use Range Blocking in SSRF Guard
OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-reserved ranges to bypass SSRF policy checks. Attackers with network reachability to special-use IPv4 ranges can exploit webfetch functionality to access blocked addresses such as 198.18.0.0/15 and other non-global ranges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.2.22
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32019?
The severity of CVE-2026-32019 is classified as medium due to the potential for attackers to bypass SSRF policy checks.
How do I fix CVE-2026-32019?
To fix CVE-2026-32019, update OpenClaw to version 2026.2.22 or later to ensure complete IPv4 special-use range validation.
What types of systems are affected by CVE-2026-32019?
CVE-2026-32019 affects OpenClaw versions prior to 2026.2.22, specifically involving incomplete handling of IPv4 special-use ranges.
Can CVE-2026-32019 lead to unauthorized access?
Yes, CVE-2026-32019 can allow attackers to exploit SSRF vulnerabilities, potentially leading to unauthorized access to reserved IP ranges.
Is a patch available for CVE-2026-32019?
Yes, a patch is available in OpenClaw version 2026.2.22 which resolves the validation issue tied to CVE-2026-32019.