---
id: CVE-2026-101881
title: >-
  OpenClaw Windows Node before 2026.7.1 contains an allocation of resources
  without limits vulnerability in the gateway WebSocket transport that allows
  connected gateways to exhaust node memory
summary: >-
  OpenClaw Windows Node before 2026.7.1 contains an allocation of resources
  without limits vulnerability in the gateway WebSocket transport that allows
  connected gateways to exhaust node memory. Attackers can send an unending
  sequence of W…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: OpenClaw
product: OpenClaw Windows Node
affected:
  - windows_node < 2026.7.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:17:19.330'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101881'
references:
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a
    label: disclosure@vulncheck.com
  - url: 'https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-30T19:53:03.562709Z'
ingestedAt: '2026-09-30T20:23:19.511Z'
---

## Overview

OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
