CyberRota Analysis
AI-GeneratedOpenClaw versions prior to 2026.5.26 are vulnerable to a bypass of non-browser rate limits on WebSocket authentication attempts, which can be exploited by lower-trust callers. This vulnerability can lead to resource exhaustion on the gateway, potentially impacting service availability. Organizations using affected versions should prioritize remediation to mitigate the risk of denial-of-service conditions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce service availability.
Related CVEs
Other vulnerabilities affecting the same vendor(s)