OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions
Moderate severity
GitHub Reviewed
Published
Feb 21, 2026
in
openclaw/openclaw
•
Updated Mar 25, 2026
Give feedback on Dependabot alerts