CVE-2026-100527: Openclaw
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2.
Affected products
- Openclaw Openclaw: before 2026.8.2 (fixed in 2026.8.2)
Published 2026-09-26. Last modified 2026-10-05.