CVE-2026-29609: OpenClaw affected by denial of service via unbounded URL-backed media fetch
(updated )
URL-backed media fetch handling allocated the entire response payload in memory (arrayBuffer) before enforcing maxBytes, allowing oversized responses to cause memory exhaustion.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-29609 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →