Resource exhaustion in OpenClaw - CVE-2026-41408
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the Tlon media download handling path when downloading media through the bundled plugin path. A remote attacker can trigger media downloads that bypass core size, count, and cleanup limits to cause a denial of service.
This issue is limited to availability impact in a bundled plugin path.