CVE-2026-28394General(openclaw / openclaw)

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway process through memory exhaustion by parsing oversized or deeply nested HTML responses. Remote attackers can social-engineer users into fetching malicious URLs with pathological HTML structures to exhaust server memory and cause service unavailability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-07); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-07: 2Mentions · 2026-03-10: 1Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-10: 103-0703-10
Signal classification3 categories
General
133.3%
Patch
133.3%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-072
General1Patch1
2026-03-101
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 OpenClaw, Denial of Service, #CVE-2026-28394 (Medium) https://dailycve.com/openclaw-denial-of-service-cve-2026-28394-medium/

    Post summary

    A new CVE, CVE-2026-28394, has been disclosed marking a medium‑severity Denial of Service vulnerability in OpenClaw.

    0000034
    167 followersView on X
  • Renan Santos@renandnzsantos
    Patch

    The vulnerabilities (all patched in 2026.2.21): • CVE-2026-28393: Path traversal in hook transform module loading → arbitrary JavaScript execution • CVE-2026-28392: Privilege escalation in Slack slash-command handler → any DM sender could escalate • CVE-2026-28391: cmd.exe metacharacter injection in allowlist-gated exec requests • CVE-2026-28394: DoS in web_fetch tool via memory exhaustion

    Post summary

    The post lists four CVEs with technical details and notes they were all patched in 2026.2.21.

    0000014
    40 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28394 OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway process through memory… https://www.cve.org/CVERecord?id=CVE-2026-28394

    Post summary

    The post reports a denial‑of‑service flaw in OpenClaw’s web_fetch tool, but does not provide evidence of active exploitation, patches, or a PoC.

    00000177
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more