Openclaw cli: OpenClaw has a Web Fetch DoS via unbounded response parsing (CVE-2026-28394)
Description
OpenClaw CLI's web_fetch tool is vulnerable to a denial of service (DoS) condition due to unbounded response parsing. An attacker can cause the OpenClaw Gateway process to exhaust memory or become unresponsive by supplying malicious web pages with oversized response bodies or deeply nested HTML. This vulnerability affects versions prior to 2026.2.15 and has been fixed in version 2026.2.15 by capping response body size and adding parsing safeguards.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The OpenClaw CLI web_fetch tool could be exploited to crash the OpenClaw Gateway process through resource exhaustion. This occurs when the tool fetches and attempts to parse attacker-controlled web pages with extremely large or pathologically nested HTML content, leading to out-of-memory conditions or unresponsiveness. The vulnerability affects openclaw versions from 2026.1.29 up to but not including 2026.2.15. The fix implemented in version 2026.2.15 caps the downloaded response body size before parsing and adds protections against pathological HTML during Readability/DOM parsing.
Potential Impact
An attacker can induce a denial of service by tricking a user or automation that uses web_fetch into retrieving malicious URLs with oversized or deeply nested HTML responses. This causes the OpenClaw Gateway process to exhaust memory or become unresponsive, resulting in service disruption. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
A fix is available in openclaw version 2026.2.15 and later. Users should upgrade to this version or newer to mitigate the vulnerability. The fix limits the size of the response body before parsing and adds additional safeguards against pathological HTML structures. No further action is required once updated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-28394
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac245cb12601ec6a3167f21
Added to database: 10/04/2026, 12:25:47 UTC
Last enriched: 10/04/2026, 13:11:21 UTC
Last updated: 10/04/2026, 16:08:37 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.