@openclaw/voice-call (and the bundled copy shipped in openclaw) accepted media-stream WebSocket upgrades before stream validation. In reachable deployments, unauthenticated pre-start sockets could be held open and increase resource pressure.
openclaw (npm): vulnerable <= 2026.2.21-2, patched in 2026.2.22.@openclaw/voice-call (npm): vulnerable <= 2026.2.21, patched in 2026.2.22.Before this fix, the voice-call media-stream path upgraded sockets first and ran shouldAcceptStream() after a later start frame. This created a pre-auth window where remote clients could hold idle sockets without call/token validation.
Availability risk in deployments where the media-stream endpoint is reachable and streaming is enabled. Under sustained abuse, this could consume connection-related resources and degrade service for legitimate streams.
The fix adds layered controls in the media-stream path:
start frame quickly)1d8968c8a821ff1a05c294a1846b3bcb6f343794patched_versions is pre-set to 2026.2.22 so this advisory is ready to publish once npm openclaw@2026.2.22 and @openclaw/voice-call@2026.2.22 are released.
OpenClaw thanks @jiseoung for reporting.
{
"cwe_ids": [
"CWE-400",
"CWE-770"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-02T22:39:43Z",
"nvd_published_at": "2026-03-11T14:16:28Z",
"severity": "HIGH"
}