CVE-2026-100527: OpenClaw before 2026.8.2 Denial of Service via Browser Relay
OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.8.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated network source can exploit it by connecting to the Browser extension relay and maintaining silent WebSocket upgrades. No privileges or user interaction are required.
What is the operational impact?
An attacker can consume all pending-authentication slots, preventing paired browser extensions from completing Browser Relay Authentication v2. The described impact is denial of service rather than disclosure or modification of data.
Which versions need remediation?
OpenClaw versions before 2026.8.2 are affected. Upgrade to 2026.8.2 or a later version.