GHSA-j27p-hq53-9wgc: OpenClaw affected by denial of service via unbounded URL-backed media fetch
URL-backed media fetch handling allocated the entire response payload in memory (arrayBuffer) before enforcing maxBytes, allowing oversized responses to cause memory exhaustion.
References
Code Behaviors & Features
Detect and mitigate GHSA-j27p-hq53-9wgc with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →