Description
OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources and reduce availability.
Published: 2026-07-17
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions before 2026.6.1 allow an attacker to trigger a slow‑read denial of service by supplying remote media URLs that consume gateway worker resources. The flaw is a logical flaw in bandwidth handling (CWE‑770); an attacker can exhaust processing capacity and render the gateway unavailable. No direct exploitation of code or data disclosure is described, but the loss of availability can interrupt critical services and lead to operational impact.

Affected Systems

The affected product is OpenClaw from the vendor OpenClaw. All releases prior to version 2026.6.1 are vulnerable, while version 2026.6.1 and later contain the fix.

Risk and Exploitability

The CVSS score of 6 indicates medium severity. The EPSS score is reported as <1%, showing a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only ability to write or influence the configured media input paths; no special privileges are required beyond that. The exploitation scenario involves an attacker specifying a remote media URL that the gateway processes slowly, thereby exhausting worker threads or CPU cycles and degrading service availability.

Generated by OpenCVE AI on July 31, 2026 at 00:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch that updates OpenClaw to 2026.6.1 or later.
  • Restrict write or configuration access to media input paths so that only trusted users or services can supply remote media URLs.
  • Configure gateway worker resource limits or timeouts to prevent a single slow‑read operation from exhausting resources.

Generated by OpenCVE AI on July 31, 2026 at 00:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources and reduce availability.
Title OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-770
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-23T19:29:26.150Z

Reserved: 2026-07-13T16:39:22.251Z

Link: CVE-2026-62210

cve-icon Vulnrichment

Updated: 2026-07-23T19:29:18.756Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling