OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits...

zetlyn/cve-ghsa vulnerability ghsa GHSA-xxhw-cvh5-24pv cve CVE-2026-101881 known 2026-09-30

https://github.com/advisories/GHSA-xxhw-cvh5-24pv

Properties

cvss6.5
receipt
Source
GitHub advisories
Its words
6.5
Read by
field:cvss.score
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-101881",
  "cvss": {
    "score": 6.5,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 6.5,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 7.1,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-770",
      "name": "Allocation of Resources Without Limits or Throttling"
    }
  ],
  "description": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.",
  "epss": {
    "percentage": 0.00548,
    "percentile": 0.43844
  },
  "ghsa_id": "GHSA-xxhw-cvh5-24pv",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-xxhw-cvh5-24pv",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-xxhw-cvh5-24pv"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-101881"
    }
  ],
  "nvd_published_at": "2026-09-30T20:17:19Z",
  "published_at": "2026-09-30T21:32:09Z",
  "references": [
    "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-101881",
    "https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a",
    "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263",
    "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1",
    "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service",
    "https://github.com/advisories/GHSA-xxhw-cvh5-24pv"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits...",
  "type": "unreviewed",
  "updated_at": "2026-09-30T21:32:15Z",
  "url": "https://api.github.com/advisories/GHSA-xxhw-cvh5-24pv",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-770
receipt
Source
GitHub advisories
Its words
CWE-770
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-101881",
  "cvss": {
    "score": 6.5,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 6.5,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 7.1,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-770",
      "name": "Allocation of Resources Without Limits or Throttling"
    }
  ],
  "description": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.",
  "epss": {
    "percentage": 0.00548,
    "percentile": 0.43844
  },
  "ghsa_id": "GHSA-xxhw-cvh5-24pv",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-xxhw-cvh5-24pv",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-xxhw-cvh5-24pv"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-101881"
    }
  ],
  "nvd_published_at": "2026-09-30T20:17:19Z",
  "published_at": "2026-09-30T21:32:09Z",
  "references": [
    "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-101881",
    "https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a",
    "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263",
    "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1",
    "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service",
    "https://github.com/advisories/GHSA-xxhw-cvh5-24pv"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits...",
  "type": "unreviewed",
  "updated_at": "2026-09-30T21:32:15Z",
  "url": "https://api.github.com/advisories/GHSA-xxhw-cvh5-24pv",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severityhigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Its words
high
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-101881",
  "cvss": {
    "score": 6.5,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 6.5,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 7.1,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-770",
      "name": "Allocation of Resources Without Limits or Throttling"
    }
  ],
  "description": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.",
  "epss": {
    "percentage": 0.00548,
    "percentile": 0.43844
  },
  "ghsa_id": "GHSA-xxhw-cvh5-24pv",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-xxhw-cvh5-24pv",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-xxhw-cvh5-24pv"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-101881"
    }
  ],
  "nvd_published_at": "2026-09-30T20:17:19Z",
  "published_at": "2026-09-30T21:32:09Z",
  "references": [
    "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-101881",
    "https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a",
    "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263",
    "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1",
    "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service",
    "https://github.com/advisories/GHSA-xxhw-cvh5-24pv"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits...",
  "type": "unreviewed",
  "updated_at": "2026-09-30T21:32:15Z",
  "url": "https://api.github.com/advisories/GHSA-xxhw-cvh5-24pv",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits... OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.