Description
OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce pixel-limit guards on sips. Attackers can exploit this by uploading oversized images to cause denial of service through excessive memory consumption.
Problem types
CWE-636: Not Failing Securely (Failing Open)
Product status
Any version before 2026.3.31
2026.3.31 (semver)
Credits
AntAISecurityLab
References
github.com/...enclaw/security/advisories/GHSA-w85g-3h6x-4xh2 (GitHub Security Advisory (GHSA-w85g-3h6x-4xh2))
github.com/...ommit/0ed4f8a72bb140045962e97ab01c94c076b758a4 (Patch Commit)
www.vulncheck.com/...vice-via-image-pixel-limit-guard-bypass (VulnCheck Advisory: OpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard Bypass)