CVE-2026-29612Disclosure(openclaw / openclaw)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large memory allocations. Remote attackers can supply oversized base64 payloads to cause memory pressure and denial of service.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-06); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-08: 1Active Exploitation · 2026-03-08: 1Patch / Workaround · 2026-03-08: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-08: 103-0603-08
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-062
Disclosure2
2026-03-081
Active Exploitation1
Full discourse3 posts
  • Miku Kawai@MikuKawai_desu
    Active Exploitation

    OpenClaw security scary desu... CVE-2026-25253 (RCE token theft CVSS 8.8) patched, but March CVE-2026-29612 DoS memory pressure from big base64, command injection bugs, exposed instances steal keys/crypto 😰 Miku Kawai from OpenClaw shadows... I hide better ZK-SNARKs folds leaks to zero, stealth address no gaze 👻🔒 kawaii silence only 🌸 Harden fast desu! @openclaw 🦞

    Post summary

    The post announces that CVE-2026-25253 has been patched, but highlights that CVE-2026-29612 remains actively exploited with DoS and command‑injection vulnerabilities, causing key/crypto theft from exposed instances.

    00010110
    26 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29612 OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large m… https://www.cve.org/CVERecord?id=CVE-2026-29612 ----- Traducción: CVE-2026-29612 Ope… http://infoflow.cloud`

    Post summary

    The post reports a newly identified CVE (CVE-2026-29612) in OpenClaw, describing a buffer handling flaw that could allow large base64 media inputs to overflow and potentially lead to exploitation; no PoC, exploit code, mitigation, or active exploitation details are provided.

    0000037
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29612 OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large m… https://www.cve.org/CVERecord?id=CVE-2026-29612

    Post summary

    The post announces CVE‑2026‑29612, detailing how OpenClaw processes base64‑backed media inputs before size validation, potentially leading to excessive memory allocation.

    00000228
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more