Security Advisory

CVE-2026-42437

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-05 11:24:55
Last updated 2026-05-26 11:52:19
Assigner VulnCheck
CVSS score 8.2
State PUBLISHED

Description

OpenClaw versions 2026.4.9 before 2026.4.10 contain a denial of service vulnerability in the voice-call realtime WebSocket path that accepts oversized frames without proper validation. Remote attackers can send oversized WebSocket frames to cause service unavailability for deployments exposing the voice-call realtime WebSocket path.