Medium severity5.3NVD Advisory· Published Sep 26, 2026
CVE-2026-100527
CVE-2026-100527
Description
OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.