CVE-2026-35633

OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger excessive memory consumption. Attackers can send crafted HTTP error responses with large bodies to remote media endpoints, causing the application to allocate unbounded memory before failure handling occurs.
Configurations

No configuration.

History

09 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 22:16

Updated : 2026-04-13 15:02


NVD link : CVE-2026-35633

Mitre link : CVE-2026-35633

CVE.ORG link : CVE-2026-35633


JSON object : View

Products Affected

No product.

CWE
CWE-789

Memory Allocation with Excessive Size Value