HarborGuard / CVE
Back to search
HIGHCVE-2026-41334Published Modified CNA VulnCheck

CVE-2026-41334: OpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard Bypass

OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce pixel-limit guards on sips. Attackers can exploit this by uploading oversized images to cause denial of service through excessive memory consumption.

Metrics

CVSS v4.0
7.1
Severity
HIGH
Fixed in
2026.3.31
Affected Products
1

Fix available

2026.3.31
Patch commits
Affected packages
  • OpenClaw / OpenClaw
    < 2026.3.31 (from 0)
    Fixed in 2026.3.31
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N