WebSocket Rate Limit Bypass in OpenClaw by OpenClaw
CVE-2026-62220

6.3MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62220?

The OpenClaw product, specifically versions 2026.2.25 and earlier, is susceptible to a rate limit bypass vulnerability that occurs during WebSocket authentication attempts. If this feature is enabled and reachable by lower-trust inputs, malicious actors can exploit this weakness to consume excessive resources, potentially leading to degraded service availability. This vulnerability emphasizes the need for robust authentication controls and prudent configuration management to safeguard applications.

Affected Version(s)

OpenClaw 2026.2.25 < 2026.5.26

OpenClaw 2026.5.26

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ylwango613
.