CVE-2026-28452

MEDIUM

OpenClaw <2026.2.14 - DoS

Title source: llm
STIX 2.1

Description

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows attackers to consume excessive CPU, memory, and disk resources through high-expansion ZIP and TAR archives. Remote attackers can trigger resource exhaustion by providing maliciously crafted archive files during install or update operations, causing service degradation or system unavailability.

Scores

CVSS v3 5.5
EPSS 0.0017
EPSS Percentile 38.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (3)
npm/clawdbot 0npm
npm/openclaw 0 - 2026.2.14npm
openclaw/openclaw < 2026.2.14
Published Mar 05, 2026
Tracked Since Mar 06, 2026