PT-2026-35783 · Openclaw · Openclaw
Wang Dong
·
Published
2026-03-31
·
Updated
2026-04-30
·
CVE-2026-41399
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.28
Description
OpenClaw accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication budget allocation. This allows unauthenticated network attackers to exhaust socket and worker capacity, resulting in a denial of service that disrupts WebSocket availability for legitimate clients.
Recommendations
Update to version 2026.3.28.
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw