Junglewise Threat Intelligence

CVE-2026-41334: OpenClaw image decompression bomb in pixel-limit guard

CVE-2026-41334 · Severity: medium · CVSS 4 · Published 2026-04-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a library used for image processing and media handling. A flaw in the pixel-limit guard can fail to reject oversized compressed images, allowing an attacker to upload a maliciously crafted image file that consumes excessive memory when decompressed, causing a denial of service that impacts service availability.

Technical details

The vulnerability is a resource exhaustion / decompression bomb flaw (CWE-770) in OpenClaw's image input validation. The pixel-limit guard can fail open on certain image types (specifically those handled via sips), allowing oversized image inputs to pass validation and be processed by the decode, metadata, and resize backends. This causes exhaustion of gateway memory when a tiny, highly compressed "image bomb" is decompressed. The vulnerability requires only network access to an application using affected OpenClaw versions and no authentication. The fix (v2026.3.31+) rejects oversized decoded image inputs before metadata and resize operations run, failing closed on unknown image dimensions.

Affected products

  • OpenClaw openclaw <=2026.3.28

Timeline

  • 2026-04-03: disclosed: GHSA-w85g-3h6x-4xh2 published
  • 2026-03-31: patched: Fix committed; released in v2026.3.31
  • 2026-03-31: other: First stable tag with fix: v2026.3.31

References

Related threats