Impact
OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending‑authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2. The weakness is a resource exhaustion flaw (CWE‑400), leading to degraded availability for users when the Browser Relay component cannot accept new authentication requests.
Affected Systems
All installations of OpenClaw using versions earlier than 2026.8.2 are affected. The vulnerability applies to the Browser Relay extension component distributed with OpenClaw. Users running the open‑source OpenClaw product with the Browser extension enabled should verify their current version.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity risk. The EPSS score is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in CISA KEV. Attackers can exploit this flaw from any unauthenticated network source that can reach the Browser Relay’s WebSocket endpoint; by continuously upgrading a silent WebSocket connection, an attacker can exhaust all pending‑authentication slots, causing a denial of service for legitimate users until the openclaw process is restarted or the vulnerable state is mitigated.
OpenCVE Enrichment