
CVE-2026-32049 (HIGH, CVSS 7.5): OpenClaw before 2026.2.22 fails to enforce inbound media byte limits. Remote attacker, no auth required — oversized payload triggers memory spike and process instability. No exploitation known yet, but update now: https://www.redpacketsecurity.com/cve-alert-cve-2026-32049-openclaw-openclaw/
Post summary
The announcement highlights that OpenClaw before version 2026.2.22 is susceptible to memory exhaustion via oversized payloads with no authentication, but no exploitation has been observed yet.


