Junglewise Threat Intelligence

CVE-2026-100527: OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sourc

CVE-2026-100527 · Severity: medium · CVSS 5.3 · Published 2026-09-26

Executive brief

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2.

References