Resource exhaustion in OpenClaw - CVE-2026-28394
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the web_fetch tool when parsing attacker-controlled web pages with oversized response bodies or pathological HTML nesting. A remote attacker can trick a user or automation into fetching a malicious url to cause a denial of service.
User interaction or automated use of the web_fetch feature is required.