PT-2026-21345 · Openclaw · Openclaw

Steipete

·

Published

2026-02-20

·

Updated

2026-02-24

·

CVE-2026-27576

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.2.17 and below
Description OpenClaw is a personal AI assistant. The ACP bridge component accepts excessively large prompt text blocks and constructs oversized prompt payloads before sending them to the chat.send function. This issue primarily impacts local ACP clients, such as IDE integrations, when processing unusually large inputs. The vulnerability stems from uncontrolled resource consumption due to the acceptance of oversized payloads. The ACP bridge is the component affected.
Recommendations Update to version 2026.2.19 or later.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-27576
GHSA-CXPW-2G23-2VGW

Affected Products

Openclaw