Skip to main content
Vulnerability Database/CVE-2026-100527

CVE-2026-100527: OpenClaw Browser Extension DoS Vulnerability

CVE-2026-100527 is a denial of service vulnerability in OpenClaw Browser extension relay that allows attackers to exhaust authentication capacity through silent WebSocket upgrades. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2026-100527 Overview

CVE-2026-100527 is a denial of service vulnerability in OpenClaw versions prior to 2026.8.2. The flaw resides in the Browser extension relay component, which handles authentication between paired browser extensions through a WebSocket upgrade handshake. Unauthenticated attackers on the network can open silent WebSocket upgrade connections and hold every pending-authentication slot indefinitely. This exhausts the relay's finite capacity and prevents legitimate extensions from completing Browser Relay Authentication v2. The vulnerability is categorized under CWE-400: Uncontrolled Resource Consumption.

Critical Impact

Unauthenticated network attackers can block all legitimate browser extension pairings by maintaining silent WebSocket upgrades, rendering the relay unusable until pending slots are released.

Affected Products

  • OpenClaw versions before 2026.8.2
  • OpenClaw Browser extension relay component
  • Browser Relay Authentication v2 pairing workflow

Discovery Timeline

  • 2026-09-26 - CVE-2026-100527 published to NVD
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-100527

Vulnerability Analysis

The OpenClaw Browser extension relay accepts incoming WebSocket upgrade requests from browser extensions attempting to pair with the host application. Each pending connection consumes a slot in a bounded pool while the relay waits for the extension to complete Browser Relay Authentication v2. The server does not enforce an aggressive timeout or rate limit on connections that upgrade but never advance past the authentication handshake. An attacker can therefore establish WebSocket connections, perform the HTTP upgrade, and then remain silent to occupy every pending slot.

Once the pool is saturated, legitimate paired extensions cannot register with the relay. The attack produces no code execution and does not disclose data, but it fully disables the pairing feature until stale connections are reaped. The attack is unauthenticated and reachable over the network wherever the relay listens.

Root Cause

The root cause is uncontrolled resource consumption in the pending-authentication queue. The relay allocates slot capacity on upgrade acceptance rather than after successful authentication. It also lacks adequate timeouts and per-source quotas on half-open sessions, allowing a single network source to monopolize the pool.

Attack Vector

Exploitation requires only network reachability to the OpenClaw Browser relay listener. An attacker repeatedly opens WebSocket connections, completes the HTTP upgrade, and keeps each connection idle. Because no authentication credentials are needed to reach the upgrade stage, the attacker holds pending slots indefinitely. See the GitHub Security Advisory GHSA-m78m-7h3q-q938 and the VulnCheck Denial of Service Advisory for additional technical context.

Detection Methods for CVE-2026-100527

Indicators of Compromise

  • Elevated counts of concurrent WebSocket upgrade connections to the OpenClaw relay from one or a small number of source addresses.
  • Browser extensions failing Browser Relay Authentication v2 with timeout or capacity errors in OpenClaw logs.
  • Long-lived relay sessions that complete the HTTP upgrade but never emit authentication frames.

Detection Strategies

  • Instrument the relay to log pending-slot occupancy and alert when utilization approaches configured maximums.
  • Correlate failed extension pairings with the source IP distribution of active upgrade sessions.
  • Baseline normal pairing cadence and flag sudden drops in successful authentications alongside stable or rising connection counts.

Monitoring Recommendations

  • Forward OpenClaw relay logs and WebSocket connection metrics to a centralized analytics platform for threshold alerting.
  • Monitor firewall and reverse proxy telemetry for repeated WebSocket upgrade requests from unauthenticated sources.
  • Track the ratio of upgraded connections to authenticated sessions as a leading indicator of resource exhaustion.

How to Mitigate CVE-2026-100527

Immediate Actions Required

  • Upgrade OpenClaw to version 2026.8.2 or later, which addresses the pending-authentication exhaustion condition.
  • Restrict network exposure of the Browser extension relay to trusted hosts and loopback where possible.
  • Enforce short idle timeouts on WebSocket sessions that have not completed Browser Relay Authentication v2.

Patch Information

The fix is delivered in OpenClaw 2026.8.2. Review the GitHub Security Advisory GHSA-m78m-7h3q-q938 for release notes and remediation guidance. Apply the upgrade across all hosts that run the OpenClaw relay.

Workarounds

  • Place the relay behind a reverse proxy that enforces per-source connection limits and idle timeouts on WebSocket upgrades.
  • Apply host firewall rules to restrict inbound access to the relay port to known client subnets only.
  • Reduce the configured pending-authentication capacity if operationally feasible to shorten reaper intervals and limit attacker leverage.
bash
# Example reverse proxy limits for WebSocket upgrade traffic
limit_conn_zone $binary_remote_addr zone=openclaw_ws:10m;
server {
    location /relay {
        limit_conn openclaw_ws 4;
        proxy_read_timeout 15s;
        proxy_send_timeout 15s;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_pass http://127.0.0.1:8787;
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.