CVE-2026-42420
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Apr 28, 2026
Vendor
unknown
Description
OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing decoded-size limits. Attackers can exploit multiple code paths to cause memory exhaustion or denial of service through crafted base64-encoded input.