rootpwn

high · CVSS v3 7.1 · CVSS v4 7.1 · EPSS 0.00197

CVE-2026-100555

OpenClaw gateway application in Synology Chat allows DNS rebinding via attachment delivery, enabling SSRF to fetch private resources. The fl

Overview

OpenClaw gateway application in Synology Chat allows DNS rebinding via attachment delivery, enabling SSRF to fetch private resources. The flaw exists in versions 2026.7.1 through 2026.8.0. It can expose internal data to chat participants.

Description

OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the original hostname to the Synology NAS, where it could resolve to a different destination. When attachment delivery accepted a remotely influenced hostname, an attacker could use DNS rebinding to make the NAS fetch a private or otherwise policy-denied resource and return its contents to the addressed conversation (server-side request forgery). Practical impact depends on NAS routing, resolver behavior, and the response available at the private destination. The issue is fixed in 2026.8.1; as a workaround, disable remote URL attachment forwarding in Synology Chat.

Impact

Confidentiality: internal files may be exfiltrated. Integrity: unauthorized data retrieval. Availability: minimal. Defenders: Synology administrators and network security teams.

Remediation

Apply patch to OpenClaw 2026.8.1 or later. Disable remote URL attachment forwarding in Synology Chat settings. Verify DNS pinning enforcement. Monitor for unauthorized attachment requests.

Risk context

Severity high, CVSS 7.1, EPSS 0.00197 indicates low probability but high impact. Urgent to patch or mitigate to prevent potential SSRF.

Affected products

  • Synology Chat
  • OpenClaw Gateway
  • Synology NAS

Scores

Severity
high
CVSS v2
5.6
CVSS v3
7.1
CVSS v4
7.1
EPSS
0.00197

SSRF DNS Rebinding Synology OpenClaw High Severity Patch Attachment Delivery

← All CVEs