CVE-2026-32019 | OpenClaw up to 2026.2.21 isPrivateIpv4 server-side request forgery (GHSA-4rqq-w8v4-7p47 / WID-SEC-2026-0472)
A vulnerability was found in OpenClaw up to 2026.2.21. It has been declared as critical. Affected is the function isPrivateIpv4. The manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2026-32019. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.