CVE-2026-32049 affects OpenClaw versions prior to 2026.2.22, stemming from a failure to consistently enforce configured inbound media byte limits before buffering remote media. This high-severity vulnerability (CVSS 7.5) allows unauthenticated remote attackers to send oversized media payloads, potentially leading to elevated memory usage and process instability. The attack vector is network-based with low complexity, requiring no privileges or user interaction. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit modules are available. Community discussion and media coverage remain minimal, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.2.22CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.22CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.