Junglewise Threat Intelligence

CVE-2026-35633: OpenClaw unbounded memory allocation in remote media fetch

CVE-2026-35633 · Severity: high · CVSS 4 · Published 2026-03-26

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI automation platform that integrates with various services and processes external media. When a remote HTTP server returns an error response, the application would read the entire error message into memory without any size limit, allowing a malicious server to cause the application to consume unbounded memory and crash. This could be exploited to cause denial of service against systems using OpenClaw.

Technical details

OpenClaw's media fetching logic (src/media/fetch.ts) did not enforce size limits on HTTP error response bodies before attempting failure handling. This is a resource consumption vulnerability (CWE-400, CWE-770) where an attacker controlling a remote server could send an arbitrarily large error response, causing OpenClaw to allocate unbounded memory until the process exhausted available resources and crashed. The attack requires network reachability to a media endpoint that OpenClaw attempts to fetch, but no authentication or user interaction. The fix (commit 81445a901091a5d27ef0b56fceedbe4724566438) routes error responses through bounded prefix reads via src/media/read-response-with-limit.ts, applying the same streaming caps and idle timeouts used for successful downloads. The patch was released in v2026.3.22 and later versions.

Affected products

  • OpenClaw openclaw < 2026.3.22

Timeline

  • 2026-03-26: disclosed: GHSA-4qwc-c7g9-4xcw published
  • 2026-03-22: patched: Fix commit 81445a901091a5d27ef0b56fceedbe4724566438
  • 2026-03-22: other: Fix released in v2026.3.22

References

Related threats