5.1
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour and DNS-SD could influence CLI routing even when actual service resolution failed. Attackers can exploit unresolved hints to steer routing decisions to unintended targets by providing malicious discovery metadata.
Basic Information
ID
CVE-2026-35659
Source
VulnCheck
Published
Apr 10, 2026 at 16:03
Modified
Apr 10, 2026 at 16:58
Affected Product
Vendor
OpenClaw
Product
OpenClaw
Affected Versions
OpenClaw OpenClaw 0
CWE Classification
References
- github.com /openclaw/openclaw/security/advisories/GHSA-rvqr-hrcc-j9vv
- github.com /openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87
- github.com /openclaw/openclaw/commit/deecf68b59a9b7eea978e40fd3c2fe543087b569
- www.vulncheck.com /advisories/openclaw-unresolved-service-metadata-routing-via-bonjour-and-dns-sd-discovery