GHSA-2rm8-9g74-xwqpMediumCVSS 5.3

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension...

Published
September 26, 2026
Last Modified
September 26, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2.

🔗 References (4)