Resource Exhaustion Vulnerability in OpenClaw Media Downloads
CVE-2026-41408

2.3LOW

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-41408?

OpenClaw, prior to version 2026.3.31, is susceptible to a resource exhaustion vulnerability that allows attackers to bypass built-in file size and download limits. This loophole can be exploited to download a large number of media files, consuming excessive disk space and affecting the availability of the affected system. Security measures intended to prevent such resource management issues may be rendered ineffective by this vulnerability, thus necessitating immediate attention and remediation.

Affected Version(s)

OpenClaw 0 < 2026.3.31

OpenClaw 2026.3.31

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AntAISecurityLab
.