high · CVSS v3 7.1 · CVSS v4 7.1 · EPSS 0.00197
CVE-2026-100555
OpenClaw gateway application in Synology Chat allows DNS rebinding via attachment delivery, enabling SSRF to fetch private resources. The fl
Overview
OpenClaw gateway application in Synology Chat allows DNS rebinding via attachment delivery, enabling SSRF to fetch private resources. The flaw exists in versions 2026.7.1 through 2026.8.0. It can expose internal data to chat participants.
Description
OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the original hostname to the Synology NAS, where it could resolve to a different destination. When attachment delivery accepted a remotely influenced hostname, an attacker could use DNS rebinding to make the NAS fetch a private or otherwise policy-denied resource and return its contents to the addressed conversation (server-side request forgery). Practical impact depends on NAS routing, resolver behavior, and the response available at the private destination. The issue is fixed in 2026.8.1; as a workaround, disable remote URL attachment forwarding in Synology Chat.
Impact
Confidentiality: internal files may be exfiltrated. Integrity: unauthorized data retrieval. Availability: minimal. Defenders: Synology administrators and network security teams.
Remediation
Apply patch to OpenClaw 2026.8.1 or later. Disable remote URL attachment forwarding in Synology Chat settings. Verify DNS pinning enforcement. Monitor for unauthorized attachment requests.
Risk context
Severity high, CVSS 7.1, EPSS 0.00197 indicates low probability but high impact. Urgent to patch or mitigate to prevent potential SSRF.
Affected products
- Synology Chat
- OpenClaw Gateway
- Synology NAS
Scores
- Severity
- high
- CVSS v2
- 5.6
- CVSS v3
- 7.1
- CVSS v4
- 7.1
- EPSS
- 0.00197