Impact
OpenClaw versions before 2026.6.1 allow an attacker to trigger a slow‑read denial of service by supplying remote media URLs that consume gateway worker resources. The flaw is a logical flaw in bandwidth handling (CWE‑770); an attacker can exhaust processing capacity and render the gateway unavailable. No direct exploitation of code or data disclosure is described, but the loss of availability can interrupt critical services and lead to operational impact.
Affected Systems
The affected product is OpenClaw from the vendor OpenClaw. All releases prior to version 2026.6.1 are vulnerable, while version 2026.6.1 and later contain the fix.
Risk and Exploitability
The CVSS score of 6 indicates medium severity. The EPSS score is reported as <1%, showing a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only ability to write or influence the configured media input paths; no special privileges are required beyond that. The exploitation scenario involves an attacker specifying a remote media URL that the gateway processes slowly, thereby exhausting worker threads or CPU cycles and degrading service availability.
OpenCVE Enrichment