PT-2026-26731 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-02
·
Updated
2026-03-21
·
CVE-2026-32049
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.22
Description
The software does not consistently enforce configured inbound media byte limits before buffering remote media across multiple channel ingestion paths. This can allow remote attackers to send oversized media payloads, potentially leading to elevated memory usage and process instability.
Recommendations
Update OpenClaw to version 2026.2.22 or later.
Fix
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw