Executive brief
OpenClaw, a tool used for managing media and gateway workers, is vulnerable to a denial-of-service attack. By providing specially crafted links to remote media, an attacker can tie up the system's resources, potentially causing the service to become slow or completely unavailable to legitimate users. This could disrupt business operations and impact the reliability of the gateway services.
Technical details
A denial of service (DoS) vulnerability exists in OpenClaw due to uncontrolled resource consumption (CWE-770/CWE-400) when processing remote media URLs. The root cause is the lack of proper throttling or limits during media retrieval, allowing for 'slow-read' attacks. An authenticated attacker with network access to configured input paths can supply malicious URLs that exhaust gateway worker resources. This results in high availability impact but does not affect confidentiality or integrity. The issue is resolved in version 2026.6.1.
Affected products
- OpenClaw OpenClaw < 2026.6.1
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-16: advisory: VulnCheck advisory published
- 2026-07-17: disclosed: NVD publication date