Skip to main content
Vulnerability Database/CVE-2026-100558

CVE-2026-100558: OpenClaw Gateway Listener DOS Vulnerability

CVE-2026-100558 is a denial of service vulnerability in OpenClaw Gateway listener that lets attackers exhaust resources through malformed WebSocket requests. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-100558 Overview

CVE-2026-100558 is a resource exhaustion vulnerability [CWE-400] in OpenClaw versions before 2026.8.1. The flaw resides in the Gateway listener, which fails to release response sockets when clients send WebSocket upgrade requests without matching connection semantics. Unauthenticated attackers can repeatedly send malformed upgrade requests to retain listener sockets and exhaust available resources. The attack bypasses the WebSocket pre-authentication connection budget, allowing a single remote attacker to cause denial of service against the Gateway without consuming the protective rate limit.

Critical Impact

Remote, unauthenticated attackers can exhaust OpenClaw Gateway listener resources and cause a denial of service by sending malformed WebSocket upgrade requests that evade pre-auth connection limits.

Affected Products

  • OpenClaw versions prior to 2026.8.1
  • OpenClaw Gateway listener component
  • Deployments exposing the Gateway WebSocket endpoint to untrusted networks

Discovery Timeline

  • 2026-09-26 - CVE-2026-100558 published to NVD
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-100558

Vulnerability Analysis

The vulnerability affects the OpenClaw Gateway listener, which accepts incoming WebSocket upgrade requests from clients. The Gateway enforces a pre-authentication connection budget to limit how many unauthenticated WebSocket sessions can be held open at once. This budget is the primary protection against connection flooding by anonymous clients.

The flaw lies in how the listener handles malformed upgrade requests. When a client sends an HTTP upgrade request that does not satisfy the expected WebSocket connection semantics, the listener produces a response but fails to release the underlying response socket. The socket remains allocated to the listener, consuming file descriptors, buffers, and worker slots.

Because the malformed exchange never completes the WebSocket handshake, it does not count against the pre-auth connection budget. An attacker can repeat the request indefinitely until the Gateway runs out of listener resources and stops accepting legitimate traffic.

Root Cause

The root cause is improper lifecycle management of response sockets during failed WebSocket upgrades. The listener treats a response as sent while leaving the socket referenced, and the pre-auth accounting path is only reached by well-formed handshakes. This mismatch between resource allocation and resource accounting is characteristic of CWE-400 (Uncontrolled Resource Consumption).

Attack Vector

The attack vector is remote and network-based. An unauthenticated attacker opens TCP connections to the Gateway listener and issues HTTP upgrade requests whose headers do not match the connection semantics the Gateway expects for a valid WebSocket session. Each request causes the listener to retain a response socket. By looping this behavior across many connections, the attacker drains the finite listener pool. No credentials, user interaction, or privileged position are required. See the GitHub Security Advisory GHSA-4r25-35qc-fr6j and the VulnCheck Advisory for OpenClaw for additional context.

No verified proof-of-concept code is available. The vulnerability mechanism is described in prose above based on vendor advisory details.

Detection Methods for CVE-2026-100558

Indicators of Compromise

  • Sustained bursts of HTTP upgrade requests to the Gateway listener from a small number of source addresses
  • Rising counts of half-open or lingering TCP connections on the Gateway port without corresponding authenticated WebSocket sessions
  • Gateway process file descriptor usage climbing toward operating system limits
  • Legitimate clients receiving connection refusals or timeouts while the Gateway process remains running

Detection Strategies

  • Inspect HTTP traffic for upgrade requests that lack the required Upgrade: websocket and Connection: Upgrade header pair or carry inconsistent handshake values
  • Correlate socket allocation metrics with completed WebSocket handshake counts to surface divergence
  • Alert when a single source IP issues a high rate of WebSocket upgrade attempts that never transition to an established session

Monitoring Recommendations

  • Export Gateway listener metrics for active sockets, accepted connections, and completed handshakes to a centralized monitoring system
  • Track pre-auth connection budget utilization alongside raw socket counts to detect accounting bypass
  • Monitor process-level file descriptor and memory usage for the Gateway and alert on rapid growth

How to Mitigate CVE-2026-100558

Immediate Actions Required

  • Upgrade OpenClaw to version 2026.8.1 or later on every host running the Gateway listener
  • Restrict network reachability of the Gateway to trusted sources until the upgrade is complete
  • Review Gateway logs for prior patterns of malformed upgrade requests to confirm whether exploitation has already been attempted

Patch Information

OpenClaw version 2026.8.1 contains the fix. Refer to the GitHub Security Advisory GHSA-4r25-35qc-fr6j for the authoritative patch notes and the VulnCheck Advisory for OpenClaw for additional remediation guidance.

Workarounds

  • Place the Gateway behind a reverse proxy or load balancer that enforces strict WebSocket handshake validation and drops malformed upgrade requests before they reach the listener
  • Apply per-source rate limits on HTTP upgrade attempts to the Gateway port at the network edge
  • Lower operating system limits on idle socket retention and tune TCP keepalive to reclaim lingering connections more aggressively
bash
# Configuration example
# No vendor-supplied configuration snippet is available for this advisory.
# Follow the upgrade instructions in GHSA-4r25-35qc-fr6j.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.