CVE-2026-62210: OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs
OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources and reduce availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.1 - Compensating control
Mitigate slow-read DoS risk by restricting which remote media URLs/inputs can be provided to OpenClaw when attackers have access to configured input paths.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62210?
The severity of CVE-2026-62210 is classified as medium with a score of 6.
How do I fix CVE-2026-62210?
To fix CVE-2026-62210, upgrade OpenClaw to version 2026.6.1 or later.
What type of vulnerability is CVE-2026-62210?
CVE-2026-62210 is a denial of service vulnerability.
What can attackers do with CVE-2026-62210?
Attackers can exploit CVE-2026-62210 to perform slow-read attacks, exhausting gateway worker resources.
Which versions of OpenClaw are affected by CVE-2026-62210?
OpenClaw versions prior to 2026.6.1 are affected by CVE-2026-62210.