CVE-2026-100527
Received Received - Intake

Denial of Service in OpenClaw Browser Extension

Vulnerability report for CVE-2026-100527, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw to 2026.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenClaw before version 2026.8.2 has a denial of service vulnerability in its Browser extension relay. Unauthenticated attackers can exhaust the system's pending-authentication capacity by maintaining silent WebSocket upgrades. This blocks legitimate paired extensions from completing Browser Relay Authentication v2.

Detection Guidance

Monitor WebSocket connections to the OpenClaw Browser Relay endpoint for unusually high numbers of pending authentication slots. Check for silent WebSocket upgrades that remain open without completing the Browser Relay Authentication v2 process. Inspect network traffic for repeated connection attempts to the relay route.

Impact Analysis

This vulnerability allows attackers to disrupt the functionality of OpenClaw's Browser extension relay. Legitimate users may be unable to authenticate or use paired extensions due to exhausted pending slots. The attack requires no privileges or user interaction and can be executed remotely over the network.

Compliance Impact

This vulnerability primarily causes a denial of service by exhausting pending-authentication capacity, which could disrupt services but does not directly expose sensitive data or violate compliance requirements like GDPR or HIPAA. However, prolonged service disruption may impact availability obligations under these standards.

Mitigation Strategies

Upgrade OpenClaw to version 2026.8.2 or later. Restrict network access to the Browser extension relay route. Avoid exposing the relay to lower-trust networks. Restart the relay if its pending-authentication capacity becomes saturated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100527. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart