CVE-2026-28394 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway process through…
Medium CVSS: 6.9

CVE-2026-28394

OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway process through memory exhaustion by parsing oversized or deeply nested HTML responses. Remote attackers can social-engineer users into fetching malicious URLs with pathological HTML structures to exhaust server memory and cause service unavailability.
Vendor
Openclaw
Product
Openclaw
CWE
CWE-770
Yayın Tarihi
2026-03-05 22:16:15
Güncelleme
2026-03-09 20:28:46
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar