Allocation of Resources Without Limits or Throttling in OpenClaw - #VU126444
Published: April 17, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the voice-call realtime WebSocket path when handling oversized WebSocket frames. A remote attacker can send oversized WebSocket frames to cause a denial of service.
Only deployments exposing that webhook path are vulnerable.