CVE-2026-29612: OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding
OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large memory allocations. Remote attackers can supply oversized base64 payloads to cause memory pressure and denial of service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29612?
CVE-2026-29612 is considered to be a high severity vulnerability due to its potential for denial of service via large memory allocations.
How do I fix CVE-2026-29612?
To fix CVE-2026-29612, update OpenClaw to version 2026.2.14 or later to ensure proper handling of base64 media file decoding.
What type of vulnerability is CVE-2026-29612?
CVE-2026-29612 is a denial of service vulnerability that affects versions of OpenClaw prior to 2026.2.14.
Who is affected by CVE-2026-29612?
Any users or applications utilizing OpenClaw versions below 2026.2.14 are potentially affected by CVE-2026-29612.
Can CVE-2026-29612 be exploited remotely?
Yes, CVE-2026-29612 can be exploited remotely by attackers who supply oversized base64-backed media inputs.