OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits...
zetlyn/cve-ghsa vulnerability ghsa GHSA-xxhw-cvh5-24pv cve CVE-2026-101881 known 2026-09-30
https://github.com/advisories/GHSA-xxhw-cvh5-24pv
Properties
| cvss | 6.5receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-101881",
"cvss": {
"score": 6.5,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.5,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_v4": {
"score": 7.1,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-770",
"name": "Allocation of Resources Without Limits or Throttling"
}
],
"description": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.",
"epss": {
"percentage": 0.00548,
"percentile": 0.43844
},
"ghsa_id": "GHSA-xxhw-cvh5-24pv",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-xxhw-cvh5-24pv",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-xxhw-cvh5-24pv"
},
{
"type": "CVE",
"value": "CVE-2026-101881"
}
],
"nvd_published_at": "2026-09-30T20:17:19Z",
"published_at": "2026-09-30T21:32:09Z",
"references": [
"https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5",
"https://nvd.nist.gov/vuln/detail/CVE-2026-101881",
"https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a",
"https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263",
"https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1",
"https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service",
"https://github.com/advisories/GHSA-xxhw-cvh5-24pv"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits...",
"type": "unreviewed",
"updated_at": "2026-09-30T21:32:15Z",
"url": "https://api.github.com/advisories/GHSA-xxhw-cvh5-24pv",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| cwe | CWE-770receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-101881",
"cvss": {
"score": 6.5,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.5,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_v4": {
"score": 7.1,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-770",
"name": "Allocation of Resources Without Limits or Throttling"
}
],
"description": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.",
"epss": {
"percentage": 0.00548,
"percentile": 0.43844
},
"ghsa_id": "GHSA-xxhw-cvh5-24pv",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-xxhw-cvh5-24pv",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-xxhw-cvh5-24pv"
},
{
"type": "CVE",
"value": "CVE-2026-101881"
}
],
"nvd_published_at": "2026-09-30T20:17:19Z",
"published_at": "2026-09-30T21:32:09Z",
"references": [
"https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5",
"https://nvd.nist.gov/vuln/detail/CVE-2026-101881",
"https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a",
"https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263",
"https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1",
"https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service",
"https://github.com/advisories/GHSA-xxhw-cvh5-24pv"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits...",
"type": "unreviewed",
"updated_at": "2026-09-30T21:32:15Z",
"url": "https://api.github.com/advisories/GHSA-xxhw-cvh5-24pv",
"vulnerabilities": [],
"withdrawn_at": null
} |
| severity | high From 7.0 to 8.9. receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-101881",
"cvss": {
"score": 6.5,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.5,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_v4": {
"score": 7.1,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-770",
"name": "Allocation of Resources Without Limits or Throttling"
}
],
"description": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.",
"epss": {
"percentage": 0.00548,
"percentile": 0.43844
},
"ghsa_id": "GHSA-xxhw-cvh5-24pv",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-xxhw-cvh5-24pv",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-xxhw-cvh5-24pv"
},
{
"type": "CVE",
"value": "CVE-2026-101881"
}
],
"nvd_published_at": "2026-09-30T20:17:19Z",
"published_at": "2026-09-30T21:32:09Z",
"references": [
"https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5",
"https://nvd.nist.gov/vuln/detail/CVE-2026-101881",
"https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a",
"https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263",
"https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1",
"https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service",
"https://github.com/advisories/GHSA-xxhw-cvh5-24pv"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits...",
"type": "unreviewed",
"updated_at": "2026-09-30T21:32:15Z",
"url": "https://api.github.com/advisories/GHSA-xxhw-cvh5-24pv",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits...
OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.