Ad

CVE-2026-35659

MEDIUM CVSS 4.0: 5.1 EPSS 0.01%
Updated Apr 10, 2026
OpenClaw
Parameter Value
CVSS 5.1 (MEDIUM)
Affected Versions before 2026.3.22
Type CWE-345 (Insufficient Verification of Data)
Vendor OpenClaw
Public PoC No

OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour and DNS-SD could influence CLI routing even when actual service resolution failed. Attackers can exploit unresolved hints to steer routing decisions to unintended targets by providing malicious discovery metadata.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v4.0