PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100558 OpenClaw CVE debrief

CVE-2026-100558 is a resource exhaustion vulnerability in OpenClaw versions before 2026.8.1. The vulnerability allows unauthenticated clients to cause denial of service by sending malformed WebSocket upgrade requests. This issue affects OpenClaw deployments, which should assess exposure and prioritize patching to prevent resource exhaustion attacks. The vulnerability is triggered by unauthenticated clients sending WebSocket upgrade requests without matching connection semantics, leading to resource exhaustion and denial of service.

Vendor
OpenClaw
Product
Unknown
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Defenders responsible for OpenClaw deployments should assess exposure and prioritize patching to prevent resource exhaustion attacks. OpenClaw operators, security teams, and vulnerability management teams should verify OpenClaw versions and apply patches. Platform and asset owners should review compensating controls for exposed systems and monitor for suspicious activity. Security teams should track exceptions, retest remediated assets, and close the item.

Why it matters

CVE-2026-100558 is a resource exhaustion vulnerability in OpenClaw versions before 2026.8.1, allowing unauthenticated clients to cause denial of service. Defenders should prioritize verifying OpenClaw versions and applying patches.

  • Denial of service through resource exhaustion
  • Potential for unauthenticated attacks
  • Need for version verification and patching

Technical summary

The vulnerability allows unauthenticated clients to cause denial of service by sending malformed WebSocket upgrade requests to OpenClaw versions before 2026.8.1. This issue is triggered by WebSocket upgrade requests without matching connection semantics, leading to resource exhaustion. Defenders should prioritize verifying OpenClaw versions and applying patches to prevent resource exhaustion attacks. The vulnerability affects OpenClaw deployments, and defenders should assess exposure and prioritize patching. The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is needed.

Defensive priority

Defenders should prioritize verifying OpenClaw versions and applying patches to prevent resource exhaustion attacks.

Recommended defensive actions

  • Verify OpenClaw versions and apply patches
  • Monitor for suspicious WebSocket upgrade requests
  • Implement rate limiting on WebSocket connections
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Additional information on affected versions and remediation is needed. OpenClaw versions before 2026.8.1 are vulnerable. Defenders should verify OpenClaw versions and apply patches. The CVE Program and NVD provide official records, but further details on exploitation and mitigation are required.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100558 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100558

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100558 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100558

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.