Description
OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebSocket frames before start validation. Remote attackers can send oversized pre-start WebSocket frames to cause resource consumption and denial of service.
Problem types
CWE-770: Allocation of Resources Without Limits or Throttling
Product status
Any version before 2026.3.31
2026.3.31 (semver)
Credits
风间映川 (@Kazamayc)
References
github.com/...enclaw/security/advisories/GHSA-2w79-r9g8-wmcr (GitHub Security Advisory (GHSA-2w79-r9g8-wmcr))
github.com/...ommit/9abcfdadf591bf266d85fbdfe14ae833e557a110 (Patch Commit)
www.vulncheck.com/...versized-websocket-frames-in-voice-call (VulnCheck Advisory: OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call)