Home

Description

OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger excessive memory consumption. Attackers can send crafted HTTP error responses with large bodies to remote media endpoints, causing the application to allocate unbounded memory before failure handling occurs.

PUBLISHED Reserved 2026-04-04 | Published 2026-04-09 | Updated 2026-04-14 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Problem types

Uncontrolled Memory Allocation

Product status

Default status
unaffected

Any version before 2026.3.22
affected

2026.3.22 (semver)
unaffected

Credits

Edward-x (@YLChen-007) finder

References

github.com/...enclaw/security/advisories/GHSA-4qwc-c7g9-4xcw (GitHub Security Advisory (GHSA-4qwc-c7g9-4xcw)) third-party-advisory

github.com/...ommit/630f1479c44f78484dfa21bb407cbe6f171dac87 (Patch Commit #1) patch

github.com/...ommit/81445a901091a5d27ef0b56fceedbe4724566438 (Patch Commit #2) patch

www.vulncheck.com/...cation-via-remote-media-error-responses (VulnCheck Advisory: OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses) third-party-advisory

cve.org (CVE-2026-35633)

nvd.nist.gov (CVE-2026-35633)

Download JSON