WebSocket Rate Limit Bypass in OpenClaw by OpenClaw
CVE-2026-62220
6.3MEDIUM
What is CVE-2026-62220?
The OpenClaw product, specifically versions 2026.2.25 and earlier, is susceptible to a rate limit bypass vulnerability that occurs during WebSocket authentication attempts. If this feature is enabled and reachable by lower-trust inputs, malicious actors can exploit this weakness to consume excessive resources, potentially leading to degraded service availability. This vulnerability emphasizes the need for robust authentication controls and prudent configuration management to safeguard applications.
Affected Version(s)
OpenClaw 2026.2.25 < 2026.5.26
OpenClaw 2026.5.26
