PT-2026-37009 · Openclaw · Openclaw

G0Oduser

·

Published

2026-04-17

·

Updated

2026-05-05

·

CVE-2026-42437

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw version 2026.4.9
Description A denial of service issue exists in the voice-call realtime WebSocket path. The system accepts oversized frames without proper validation, allowing remote attackers to send these frames to cause service unavailability for deployments that expose the webhook path.
Recommendations Update to version 2026.4.10 or newer.

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-42437
GHSA-VW3H-Q6XQ-JJM5

Affected Products

Openclaw