PT-2026-31768 · Openclaw · Openclaw

Edward-X

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-35633

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.22
Description OpenClaw is susceptible to an unbounded memory allocation issue in its remote media HTTP error handling. Attackers can exploit this by sending specially crafted HTTP error responses with large content to remote media endpoints. This causes the application to allocate an excessive amount of memory before error handling can take place, potentially leading to application failure.
Recommendations Update to version 2026.3.22 or later.

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-35633
GHSA-4QWC-C7G9-4XCW
GHSA-HM63-VWJ4-MJ2Q

Affected Products

Openclaw