OpenClaw: denial of service through large base64 media files allocating large buffers before limit checks
Moderate severity
GitHub Reviewed
Published
Feb 15, 2026
in
openclaw/openclaw
•
Updated Feb 18, 2026
Description
Published to the GitHub Advisory Database
Feb 18, 2026
Reviewed
Feb 18, 2026
Last updated
Feb 18, 2026
Summary
Base64-backed media inputs could be decoded into Buffers before enforcing decoded-size budgets. An attacker supplying oversized base64 payloads can force large allocations, causing memory pressure and denial of service.
Attack Scenario Notes
Affected Packages / Versions
Fixed In
Fix Commit(s)
Credits
Thanks @vincentkoc for reporting.
References