In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a… (CVE-2026-100555)
CVE-2026-100555 is a vulnerability in Synology Chat attachment delivery affecting versions from 2026.7.1 up to but not including 2026.8.1. The issue involves loss of DNS pinning in the gateway application, allowing DNS rebinding attacks that can cause the NAS to fetch unauthorized internal resources and expose their contents via server-side request forgery. The vulnerability is fixed in version 2026.8.1. As a workaround, disabling remote URL attachment forwarding in Synology Chat mitigates the risk.
AI Analysis
Technical Summary
In Synology Chat versions >= 2026.7.1 and < 2026.8.1, the OpenClaw gateway application validated only a single DNS result for a file URL but passed the original hostname to the Synology NAS. This allowed an attacker to exploit DNS rebinding by supplying a hostname that resolves differently at the NAS, enabling the NAS to fetch private or policy-denied resources and return their contents to the chat conversation. This server-side request forgery vulnerability depends on NAS routing, DNS resolver behavior, and the nature of the internal resource. The vulnerability is addressed in version 2026.8.1. Disabling remote URL attachment forwarding is a recommended workaround.
Potential Impact
An attacker able to influence the hostname in attachment delivery can exploit DNS rebinding to cause the NAS to access internal or restricted resources and disclose their contents to the chat conversation. This results in high confidentiality impact, limited integrity impact, and no availability impact. The practical impact varies based on network configuration and internal resource accessibility.
Mitigation Recommendations
The vulnerability is fixed in Synology Chat version 2026.8.1. Users should upgrade to this version to remediate the issue. As a temporary workaround, disabling remote URL attachment forwarding in Synology Chat prevents exploitation of this vulnerability.
In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a… (CVE-2026-100555)
Description
CVE-2026-100555 is a vulnerability in Synology Chat attachment delivery affecting versions from 2026.7.1 up to but not including 2026.8.1. The issue involves loss of DNS pinning in the gateway application, allowing DNS rebinding attacks that can cause the NAS to fetch unauthorized internal resources and expose their contents via server-side request forgery. The vulnerability is fixed in version 2026.8.1. As a workaround, disabling remote URL attachment forwarding in Synology Chat mitigates the risk.
CVSS v3.1
Score 7.1high
Affected software
pkg:github/openclaw/openclawRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Synology Chat versions >= 2026.7.1 and < 2026.8.1, the OpenClaw gateway application validated only a single DNS result for a file URL but passed the original hostname to the Synology NAS. This allowed an attacker to exploit DNS rebinding by supplying a hostname that resolves differently at the NAS, enabling the NAS to fetch private or policy-denied resources and return their contents to the chat conversation. This server-side request forgery vulnerability depends on NAS routing, DNS resolver behavior, and the nature of the internal resource. The vulnerability is addressed in version 2026.8.1. Disabling remote URL attachment forwarding is a recommended workaround.
Potential Impact
An attacker able to influence the hostname in attachment delivery can exploit DNS rebinding to cause the NAS to access internal or restricted resources and disclose their contents to the chat conversation. This results in high confidentiality impact, limited integrity impact, and no availability impact. The practical impact varies based on network configuration and internal resource accessibility.
Mitigation Recommendations
The vulnerability is fixed in Synology Chat version 2026.8.1. Users should upgrade to this version to remediate the issue. As a temporary workaround, disabling remote URL attachment forwarding in Synology Chat prevents exploitation of this vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-659j-39wf-988v
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100555"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ab74f2cf7a7c54106e1383d
Added to database: 09/26/2026, 04:50:52 UTC
Last enriched: 09/26/2026, 04:55:41 UTC
Last updated: 09/27/2026, 01:47:40 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.