mediumVulnerability

GHSA-f44p-c7w9-7xr7

## Summary The gateway accepted unbounded concurrent unauthenticated WebSocket upgrades before allocating them to an authenticated session budget. ## Impact An unauthenticated network attacker could consume socket and worker capacity and disrupt WebSocket availability for legitimate clients. ## Affected Component `src/gateway/server-http.ts, src/gateway/server/preauth-connection-budget.ts` ## Fixed Versions - Affected: `<= 2026.3.24` - Patched: `>= 2026.3.28` - Latest stable `2026.3.28` contains the fix. ## Fix Fixed by commit `cb5f7e201f` (`gateway: cap concurrent pre-auth websocket upgrades`). Discovered by:Topsec AlphaLab (wang dong)

Properties

ghsa_id
GHSA-f44p-c7w9-7xr7
severity
medium
summary
OpenClaw: Gateway WebSocket Denial of Service via unbounded pre-auth upgrades
cve_id
GHSA-f44p-c7w9-7xr7
is_ghsa_only
true
ghsa_published
2026-03-31T23:54:00Z
source_url
https://github.com/advisories/GHSA-f44p-c7w9-7xr7
ghsa_updated
2026-03-31T23:54:01Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (2)

[Weakness]Allocation of Resources Without Limits or Throttling
[Weakness]Uncontrolled Resource Consumption

Explore deeper with Ninja Signal's threat intelligence graph