PT-2026-23554 · Openclaw+1 · Openclaw+1

Kexinoh

·

Published

2026-02-16

·

Updated

2026-03-07

·

CVE-2026-28479

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.15
Description The software uses SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations. SHA-1 is a deprecated cryptographic hash function with known collision weaknesses. A collision in this hash could allow an attacker to cause cache poisoning, potentially leading to unsafe sandbox state reuse. The software uses deterministic IDs to determine if an existing sandbox container can be safely reused. Exploiting this issue could allow one configuration to be misinterpreted as another under the same sandbox cache identity. The implementation has been updated to use SHA-256 for these hashes to restore collision resistance.
Recommendations Update to version 2026.2.15 or later.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

BDU:2026-06170
CVE-2026-28479
GHSA-FH3F-Q9QW-93J9

Affected Products

Docker
Openclaw