Decompression Bomb Vulnerability in OpenClaw Image Processing
CVE-2026-41334

7.1HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
23 April 2026

What is CVE-2026-41334?

OpenClaw prior to version 2026.3.31 is susceptible to a decompression bomb vulnerability in its image processing functionality. This flaw occurs due to inadequate enforcement of pixel-limit guards on the Simple Image Processing System (SIPS), allowing attackers to exploit the system by uploading excessively large images. This can lead to denial of service as the application consumes excessive memory, potentially crashing the service and affecting overall availability.

Affected Version(s)

OpenClaw 0 < 2026.3.31

OpenClaw 2026.3.31

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AntAISecurityLab
.