Security Advisory

CVE-2026-28452

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-05 21:59:29
Last updated 2026-03-09 16:55:24
Assigner VulnCheck
State PUBLISHED

Description

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows attackers to consume excessive CPU, memory, and disk resources through high-expansion ZIP and TAR archives. Remote attackers can trigger resource exhaustion by providing maliciously crafted archive files during install or update operations, causing service degradation or system unavailability.