OpenClaw did not consistently enforce configured inbound media byte limits before buffering remote media in several channel ingestion paths. A remote sender could trigger oversized downloads and memory pressure before rejection.
openclaw (npm)<= 2026.2.21-2 (latest published at triage time)2026.2.22 (planned next release)An attacker could cause elevated memory usage and potential process instability (denial of service) by sending oversized media payloads.
73d93dee64127a26f1acd09d0403b794cdeb4f5cpatched_versions is pre-set to the planned next release (2026.2.22). After that npm release is published, this advisory can be published without further version-field edits.
OpenClaw thanks @tdjackey for reporting.
| Score | Percentile |
|---|---|
| 0.16% | 36.67% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 8.7 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-rxxp-482v-7mrh ↗ |
| CVE | CVE-2026-32049 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | openclaw | < 2026.2.22 | 2026.2.22 | — |