HarborGuard / CVE
Back to search
HIGHCVE-2026-28479Published Modified CNA VulnCheck

CVE-2026-28479: OpenClaw < 2026.2.15 - Cache Poisoning via Deprecated SHA-1 Hash in Sandbox Configuration

OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations, which is deprecated and vulnerable to collision attacks. An attacker can exploit SHA-1 collisions to cause cache poisoning, allowing one sandbox configuration to be misinterpreted as another and enabling unsafe sandbox state reuse.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
2026.2.15
Affected Products
1

Fix available

2026.2.15
Patch commits
Affected packages
  • OpenClaw / OpenClaw
    < 2026.2.15 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N