PT-2026-37009 · Openclaw · Openclaw

·

CVE-2026-42437

·

Published

2026-04-17

·

Updated

2026-05-05

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw version 2026.4.9
Description A denial of service issue exists in the voice-call realtime WebSocket path. The system accepts oversized frames without proper validation, allowing remote attackers to send these frames to cause service unavailability for deployments that expose the webhook path.
Recommendations Update to version 2026.4.10 or newer.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42437
GHSA-VW3H-Q6XQ-JJM5

Affected Products

Openclaw