Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-ccx3-fw7q-rr2r | OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks |
Tue, 28 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing decoded-size limits. Attackers can exploit multiple code paths to cause memory exhaustion or denial of service through crafted base64-encoded input. | |
| Title | OpenClaw < 2026.4.8 - Improper Base64 Decoding Size Validation | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-29T15:10:38.714Z
Reserved: 2026-04-27T11:38:59.195Z
Link: CVE-2026-42420
No data.
Status : Analyzed
Published: 2026-04-28T19:37:45.680
Modified: 2026-04-30T14:04:43.353
Link: CVE-2026-42420
No data.
OpenCVE Enrichment
Updated: 2026-04-28T23:00:13Z
Github GHSA