Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2959 articles · 183563 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-62220PATCHED
openclaw · openclaw

OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass

Description

OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce service availability.

Affected Products

VendorProductVersions
openclawopenclaw2026.2.25

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-5p6w-wmh3-frfr(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-websocket-rate-limit-bypass(third-party-advisory)

Related News (1 articles)

Tier C
VulDB18d ago
CVE-2026-62220 | OpenClaw up to 2026.5.25 WebSocket Authentication improper authentication
→ No new info (linked only)
CVSS 3.15.3 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.5.26
CWECWE-307
PublishedJul 17, 2026
Last enriched18d agov2
Trending Score4
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-62198
OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search
Trending: 3
NONECVE-2026-62229EXP
OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching
Trending: 3
NONECVE-2026-62207
OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools
Trending: 3
NONECVE-2026-62223
OpenClaw < 2026.5.18 Authorization Bypass via Device-pair
Trending: 3
NONECVE-2026-62203
OpenClaw < 2026.6.6 Environment Variable Injection via rustup
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 17, 2026
Discovered by ZDM
Jul 17, 2026
Updated: severity, affectedVersions, cweIds
Jul 17, 2026
Patch Available
Jul 17, 2026

Version History

v2
Last enriched 18d ago
v2Tier C18d ago

Severity upgraded to CRITICAL, affected versions extended to include 2026.5.25, and CWE-287 (Improper Authentication) added to reflect the vulnerability classification.

severityaffectedVersionscweIds
via VulDB
v118d ago

Initial creation