PT-2026-21345 · Openclaw · Openclaw
Steipete
·
Published
2026-02-20
·
Updated
2026-02-24
·
CVE-2026-27576
CVSS v4.0
4.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.2.17 and below
Description
OpenClaw is a personal AI assistant. The ACP bridge component accepts excessively large prompt text blocks and constructs oversized prompt payloads before sending them to the
chat.send function. This issue primarily impacts local ACP clients, such as IDE integrations, when processing unusually large inputs. The vulnerability stems from uncontrolled resource consumption due to the acceptance of oversized payloads. The ACP bridge is the component affected.Recommendations
Update to version 2026.2.19 or later.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw