CVE-2026-101881
Received Received - Intake

OpenClaw Windows Node Memory Exhaustion via WebSocket Frames

Vulnerability report for CVE-2026-101881, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw windows_node to 2026.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenClaw Windows Node before 2026.7.1 has a vulnerability where attackers can send endless WebSocket continuation frames without an EndOfMessage flag. This causes the node to allocate unlimited memory, leading to a crash due to unbounded memory growth.

Detection Guidance

Monitor for abnormal memory usage on OpenClaw Windows Node processes. Check for WebSocket connections sending continuous frames without EndOfMessage flags. Use network monitoring tools like Wireshark to inspect WebSocket traffic for unusually large or fragmented messages.

Impact Analysis

This vulnerability allows attackers to crash the OpenClaw Windows Node process by exhausting its memory. This can disrupt services relying on the node, cause downtime, and potentially affect other software running on the same machine.

Mitigation Strategies

Update OpenClaw Windows Node to version 2026.7.1 or later. If updating is not immediately possible, restrict WebSocket connections to trusted gateways and implement network-level rate limiting to prevent unbounded frame sequences.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101881. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart