GHSA-f44p-c7w9-7xr7

Suggest an improvement
Source
https://github.com/advisories/GHSA-f44p-c7w9-7xr7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-f44p-c7w9-7xr7/GHSA-f44p-c7w9-7xr7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f44p-c7w9-7xr7
Aliases
Downstream
Published
2026-03-31T23:54:00Z
Modified
2026-05-05T16:11:44Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: Gateway WebSocket Denial of Service via unbounded pre-auth upgrades
Details

Summary

The gateway accepted unbounded concurrent unauthenticated WebSocket upgrades before allocating them to an authenticated session budget.

Impact

An unauthenticated network attacker could consume socket and worker capacity and disrupt WebSocket availability for legitimate clients.

Affected Component

src/gateway/server-http.ts, src/gateway/server/preauth-connection-budget.ts

Fixed Versions

  • Affected: <= 2026.3.24
  • Patched: >= 2026.3.28
  • Latest stable 2026.3.28 contains the fix.

Fix

Fixed by commit cb5f7e201f (gateway: cap concurrent pre-auth websocket upgrades).

Discovered by:Topsec AlphaLab (wang dong)

Database specific
{
    "cwe_ids":  [
        "CWE-400",
        "CWE-770"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-31T23:54:00Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.3.28

Database specific

last_known_affected_version_range
"<= 2026.3.24"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-f44p-c7w9-7xr7/GHSA-f44p-c7w9-7xr7.json"