CVE-2026-29612: OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding

Published Mar 5, 2026
·
Updated

OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large memory allocations. Remote attackers can supply oversized base64 payloads to cause memory pressure and denial of service.

Affected Software

2 affected components
OpenClaw<2026.2.14
OpenClaw Openclaw Node.js<2026.2.14

Event History

Mar 5, 2026
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 26, 58161
Event
via FIRST·10:55 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-29612?

CVE-2026-29612 is considered to be a high severity vulnerability due to its potential for denial of service via large memory allocations.

2

How do I fix CVE-2026-29612?

To fix CVE-2026-29612, update OpenClaw to version 2026.2.14 or later to ensure proper handling of base64 media file decoding.

3

What type of vulnerability is CVE-2026-29612?

CVE-2026-29612 is a denial of service vulnerability that affects versions of OpenClaw prior to 2026.2.14.

4

Who is affected by CVE-2026-29612?

Any users or applications utilizing OpenClaw versions below 2026.2.14 are potentially affected by CVE-2026-29612.

5

Can CVE-2026-29612 be exploited remotely?

Yes, CVE-2026-29612 can be exploited remotely by attackers who supply oversized base64-backed media inputs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203