CVE-2026-41399

· NIST NVD ↗

OpenClaw before 2026.3.28 accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication budget allocation. Unauthenticated network attackers can exhaust socket and worker capacity to disrupt WebSocket availability for legitimate clients.

HIGH
CVSS severity
7.5
CVSS base score
2026-04-28
Published

CWE codes

CWE-770

Affected products

openclaw:openclaw

Sources