| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4qwc-c7g9-4xcw | OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 15 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 |
Tue, 14 Apr 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger excessive memory consumption. Attackers can send crafted HTTP error responses with large bodies to remote media endpoints, causing the application to allocate unbounded memory before failure handling occurs. | |
| Title | OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-789 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-14T03:10:02.033Z
Reserved: 2026-04-04T12:29:42.738Z
Link: CVE-2026-35633
Updated: 2026-04-14T03:09:55.246Z
Status : Analyzed
Published: 2026-04-09T22:16:32.187
Modified: 2026-04-15T17:02:57.023
Link: CVE-2026-35633
No data.
OpenCVE Enrichment
Updated: 2026-04-15T19:45:12Z
Github GHSA