CVE-2026-35633

OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger excessive memory consumption. Attackers can send crafted HTTP error responses with large bodies to remote media endpoints, causing the application to allocate unbounded memory before failure handling occurs.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

15 Apr 2026, 17:02

Type Values Removed Values Added
CWE CWE-770
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 - () https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 - Patch
References () https://github.com/openclaw/openclaw/commit/81445a901091a5d27ef0b56fceedbe4724566438 - () https://github.com/openclaw/openclaw/commit/81445a901091a5d27ef0b56fceedbe4724566438 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-4qwc-c7g9-4xcw - () https://github.com/openclaw/openclaw/security/advisories/GHSA-4qwc-c7g9-4xcw - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-unbounded-memory-allocation-via-remote-media-error-responses - () https://www.vulncheck.com/advisories/openclaw-unbounded-memory-allocation-via-remote-media-error-responses - Third Party Advisory

09 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 22:16

Updated : 2026-04-15 17:02


NVD link : CVE-2026-35633

Mitre link : CVE-2026-35633

CVE.ORG link : CVE-2026-35633


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-789

Memory Allocation with Excessive Size Value

CWE-770

Allocation of Resources Without Limits or Throttling