CVE-2026-32062: OpenClaw 2026.2.21-2 < 2026.2.22 - Unauthenticated WebSocket Resource Exhaustion via Media Stream
OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 accept media-stream WebSocket upgrades before stream validation, allowing unauthenticated clients to establish connections. Remote attackers can hold idle pre-authenticated sockets open to consume connection resources and degrade service availability for legitimate streams.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32062?
CVE-2026-32062 is considered a high-severity vulnerability due to its potential for resource exhaustion via unauthenticated WebSocket connections.
How do I fix CVE-2026-32062?
To fix CVE-2026-32062, upgrade OpenClaw and @openclaw/voice-call to version 2026.2.22 or later.
What types of systems are affected by CVE-2026-32062?
CVE-2026-32062 affects OpenClaw versions up to 2026.2.21-2 and @openclaw/voice-call versions up to 2026.2.21.
What is the attack vector for CVE-2026-32062?
The attack vector for CVE-2026-32062 involves unauthenticated media-stream WebSocket upgrades that can lead to resource exhaustion.
Is user authentication required to exploit CVE-2026-32062?
No, user authentication is not required to exploit CVE-2026-32062, making it particularly dangerous.