Resource Consumption Vulnerability in OpenClaw Voice-Call Component
CVE-2026-41400

6.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-41400?

The OpenClaw voice-call component prior to version 2026.3.31 contains an incomplete fix for a previous vulnerability. It allows remote attackers to send oversized WebSocket frames before proper validation has started, potentially leading to significant resource consumption and denial of service. This vulnerability emphasizes the need for effective input validation and robust error handling in WebSocket communications.

Affected Version(s)

OpenClaw 0 < 2026.3.31

OpenClaw 2026.3.31

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

风间映川 (@Kazamayc)
.