Junglewise Threat Intelligence

CVE-2026-29612: OpenClaw denial of service through large base64 buffer allocation

CVE-2026-29612 · Severity: low · CVSS 3.1 · Published 2026-02-18

Technologies: clawdbot (npm), Openclaw. Vendors: npm, Openclaw.

Executive brief

OpenClaw is a gateway framework used to handle media inputs and API requests. An attacker can send oversized base64-encoded files that are decoded into memory buffers before size limits are checked, consuming excessive RAM and causing the service to become unavailable. The risk is elevated if the gateway is exposed to untrusted networks or has weak authentication controls.

Technical details

The vulnerability is an uncontrolled resource consumption flaw (CWE-400, CWE-770) in how OpenClaw and ClawdBot handle base64-encoded media inputs. The root cause is that base64 payloads are decoded into in-memory buffers before the decoded-size budget limits are enforced. An attacker with local or authenticated access can supply maliciously large base64 payloads to trigger unbounded memory allocations, causing memory pressure and denial of service. The attack requires local access or authenticated HTTP endpoints; however, if deployments expose the gateway to untrusted networks or disable rate limiting, the severity increases to a network-reachable DoS. OpenClaw has a patched version (2026.2.14) available; ClawdBot has no patched release and users are advised to migrate to OpenClaw.

Affected products

  • OpenClaw openclaw ≤ 2026.2.13
  • OpenClaw clawdbot ≤ 2026.1.24-3

Timeline

  • 2026-02-18: disclosed
  • 2026-02-18: patched: openclaw 2026.2.14 (planned patch)
  • 2026-03-05: other: CVE-2026-29612 published to NVD

References

Related threats