medium · CVSS v3 5.3 · CVSS v4 6.9 · EPSS 0.00349
CVE-2026-100527
OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthent…
Description
OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- 6.9
- EPSS
- 0.00349