


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.28 accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication budget allocation. Unauthenticated network …
Published:
27 April 2026 at 22:00:00
Alert date:
28 April 2026 at 20:08:59
Source:
nvd.nist.gov
Web Technologies, Network Infrastructure
CVE-2026-41399 affects OpenClaw versions before 2026.3.28, allowing unauthenticated attackers to perform denial of service attacks through unbounded concurrent WebSocket upgrades. The vulnerability exists due to lack of pre-authentication budget allocation for WebSocket connections. Attackers can exploit this flaw to exhaust socket and worker capacity, disrupting WebSocket availability for legitimate users. This is a network-based attack that requires no authentication, making it easily exploitable by remote attackers. The impact is a complete disruption of WebSocket services for legitimate clients.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41399
https://github.com/openclaw/openclaw/security/advisories/GHSA-f44p-c7w9-7xr7
https://www.vulncheck.com/advisories/openclaw-denial-of-service-via-unbounded-pre-auth-websocket-upgrades
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
