CVE-2026-40037: OpenClaw < 2026.3.31 - Unsafe Request Body Replay via fetchWithSsrFGuard Cross-Origin Redirects
Impact
fetchWithSsrFGuard replays unsafe request bodies across cross-origin redirects.
A guarded fetch could resend unsafe request bodies or headers when following cross-origin redirects.
OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi-tenant service boundary.
Affected Packages / Versions
- Package: openclaw (npm) - Affected versions: <2026.3.31 - Patched versions: 2026.4.8
Fix
The issue was fixed on main and is available in the patched npm version listed above. The verified fixed tree is commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5.
Verification
The fix was re-checked against main before publication, including targeted regression tests for the affected security boundary.
Credits
Thanks @BG0ECV for reporting.
Other sources
OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering redirects to exfiltrate sensitive request data or headers to unintended origins.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/openclawto a version that resolves this vulnerability.Fixed in 2026.4.8 - Upgrade
Upgrade
openclaw (npm)to a version that resolves this vulnerability.Fixed in 2026.4.8 - Compensating control
As a mitigation before upgrading, ensure cross-origin redirects cannot cause unsafe request bodies/headers to be followed to unintended origins (e.g., block/limit redirect targets to trusted origins at the application/network layer).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40037?
CVE-2026-40037 is considered a high severity vulnerability due to its potential to replay unsafe request bodies across cross-origin redirects.
How do I fix CVE-2026-40037?
To fix CVE-2026-40037, update OpenClaw to version 2026.4.8 or later.
What is the impact of CVE-2026-40037?
The impact of CVE-2026-40037 includes the possibility of unsafe request bodies being sent inadvertently during cross-origin redirects.
Which versions of OpenClaw are affected by CVE-2026-40037?
OpenClaw versions prior to 2026.4.8 are affected by CVE-2026-40037.
What is fetchWithSsrFGuard in relation to CVE-2026-40037?
fetchWithSsrFGuard is a function in OpenClaw that improperly handles request bodies during cross-origin redirects, leading to CVE-2026-40037.