Image pixel-limit guard can fail open on sips and allow decompression-bomb DoS
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.310ed4f8a72bb140045962e97ab01c94c076b758a4 — 2026-03-31T22:52:55+09:00OpenClaw thanks @AntAISecurityLab for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T03:01:18Z",
"cwe_ids": [
"CWE-770"
],
"severity": "MODERATE",
"nvd_published_at": null
}