CVE-2026-35633: OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure
(updated )
Remote media HTTP error bodies were read without a hard size cap before failure handling, allowing unbounded allocation on error responses.
References
- github.com/advisories/GHSA-4qwc-c7g9-4xcw
- github.com/openclaw/openclaw
- github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87
- github.com/openclaw/openclaw/commit/81445a901091a5d27ef0b56fceedbe4724566438
- github.com/openclaw/openclaw/security/advisories/GHSA-4qwc-c7g9-4xcw
- nvd.nist.gov/vuln/detail/CVE-2026-35633
- www.vulncheck.com/advisories/openclaw-unbounded-memory-allocation-via-remote-media-error-responses
Code Behaviors & Features
Detect and mitigate CVE-2026-35633 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →