PatchSiren cyber security CVE debrief
CVE-2026-100558 OpenClaw CVE debrief
CVE-2026-100558 is a resource exhaustion vulnerability in OpenClaw versions before 2026.8.1. The vulnerability allows unauthenticated clients to cause denial of service by sending malformed WebSocket upgrade requests. This issue affects OpenClaw deployments, which should assess exposure and prioritize patching to prevent resource exhaustion attacks. The vulnerability is triggered by unauthenticated clients sending WebSocket upgrade requests without matching connection semantics, leading to resource exhaustion and denial of service.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for OpenClaw deployments should assess exposure and prioritize patching to prevent resource exhaustion attacks. OpenClaw operators, security teams, and vulnerability management teams should verify OpenClaw versions and apply patches. Platform and asset owners should review compensating controls for exposed systems and monitor for suspicious activity. Security teams should track exceptions, retest remediated assets, and close the item.
Why it matters
CVE-2026-100558 is a resource exhaustion vulnerability in OpenClaw versions before 2026.8.1, allowing unauthenticated clients to cause denial of service. Defenders should prioritize verifying OpenClaw versions and applying patches.
- Denial of service through resource exhaustion
- Potential for unauthenticated attacks
- Need for version verification and patching
Technical summary
The vulnerability allows unauthenticated clients to cause denial of service by sending malformed WebSocket upgrade requests to OpenClaw versions before 2026.8.1. This issue is triggered by WebSocket upgrade requests without matching connection semantics, leading to resource exhaustion. Defenders should prioritize verifying OpenClaw versions and applying patches to prevent resource exhaustion attacks. The vulnerability affects OpenClaw deployments, and defenders should assess exposure and prioritize patching. The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is needed.
Defensive priority
Defenders should prioritize verifying OpenClaw versions and applying patches to prevent resource exhaustion attacks.
Recommended defensive actions
- Verify OpenClaw versions and apply patches
- Monitor for suspicious WebSocket upgrade requests
- Implement rate limiting on WebSocket connections
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Additional information on affected versions and remediation is needed. OpenClaw versions before 2026.8.1 are vulnerable. Defenders should verify OpenClaw versions and apply patches. The CVE Program and NVD provide official records, but further details on exploitation and mitigation are required.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100558 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100558
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100558 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100558
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-4r25-35qc-fr6j
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-resource-exhaustion-via-websocket-upgrade
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.