CVE-2026-35629 | OpenClaw up to 2026.3.24 Destination fetch server-side request forgery (GHSA-rhfg-j8jq-7v2h)
A vulnerability described as critical has been identified in OpenClaw up to 2026.3.24. This vulnerability affects the function fetch of the component Destination Handler. Executing a manipulation can lead to server-side request forgery.
This vulnerability appears as CVE-2026-35629. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.