Junglewise Threat Intelligence

OpenClaw inbound media byte limit bypass

Severity: low · CVSS 3.1 · Published 2026-03-21

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a media communication platform that enforces configured size limits on incoming media files. Due to incomplete enforcement of these limits across multiple ingestion paths, attackers can send oversized media files that consume excessive memory before being rejected, potentially causing the service to become unstable or crash.

Technical details

OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple channel ingestion paths, a resource consumption vulnerability (CWE-770). An unauthenticated remote attacker can send oversized media payloads to the service, triggering elevated memory allocation and potential process instability before the size check rejects them. The vulnerability affects multiple ingestion code paths, allowing bypass of the intended size restriction mechanism. The issue was patched in version 2026.2.22.

Affected products

  • OpenClaw OpenClaw < 2026.2.22

Timeline

  • 2026-02-23: disclosed
  • 2026-02-23: patched: Fix planned for version 2026.2.22
  • 2026-03-21: advisory

References

Related threats