CVE-2026-41334
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
23/04/2026
Last modified:
24/04/2026
Description
OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce pixel-limit guards on sips. Attackers can exploit this by uploading oversized images to cause denial of service through excessive memory consumption.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM



