CVE-2026-28452

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
05/03/2026
Last modified:
05/03/2026

Description

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows attackers to consume excessive CPU, memory, and disk resources through high-expansion ZIP and TAR archives. Remote attackers can trigger resource exhaustion by providing maliciously crafted archive files during install or update operations, causing service degradation or system unavailability.