PT-2026-35783 · Openclaw · Openclaw

Wang Dong

·

Published

2026-03-31

·

Updated

2026-04-30

·

CVE-2026-41399

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.28
Description OpenClaw accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication budget allocation. This allows unauthenticated network attackers to exhaust socket and worker capacity, resulting in a denial of service that disrupts WebSocket availability for legitimate clients.
Recommendations Update to version 2026.3.28.

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41399
GHSA-F44P-C7W9-7XR7

Affected Products

Openclaw