Resource exhaustion in OpenClaw - #VU149033
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the Browser extension relay\'s global pending-authentication pool when processing unauthenticated WebSocket upgrades. A remote attacker can reserve all pending authentication slots before proving possession of the relay key to cause a denial of service.
Paired Chrome extensions cannot complete Browser Relay Authentication v2 while the pending-authentication capacity is saturated.