---
id: CVE-2026-100558
title: >-
  OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability
  in the Gateway listener that allows unauthenticated clients to retain response
  sockets by sending WebSocket upgrade requests without matching connection
  semant…
summary: >-
  OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability
  in the Gateway listener that allows unauthenticated clients to retain response
  sockets by sending WebSocket upgrade requests without matching connection
  semant…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.8.1
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T03:17:02.533'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100558'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-4r25-35qc-fr6j
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-resource-exhaustion-via-websocket-upgrade
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T03:25:24.684Z'
---

## Overview

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attackers can repeatedly send malformed upgrade requests to exhaust listener resources and cause denial of service without consuming the WebSocket pre-auth connection budget.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
