Resource exhaustion in OpenClaw - CVE-2026-28452
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in src/infra/archive.ts extractArchive when processing high-expansion ZIP or TAR archives during install or update flows. A remote attacker can supply a specially crafted archive to cause a denial of service.