rootpwn

medium · CVSS v3 5.3 · CVSS v4 6.9 · EPSS 0.00349

CVE-2026-100527

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthent…

Description

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2.

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
6.9
EPSS
0.00349

← All CVEs