Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Untriaged
created 1 day ago
OpenClaw 2026.2.21-2 < 2026.2.22 - Unauthenticated WebSocket Resource Exhaustion via Media Stream

OpenClaw versions2026.2.21-2 prior to 2026.2.22 and @openclaw/voice-call versions 2026.2.21 prior to 2026.2.22 accept media-stream WebSocket upgrades before stream validation, allowing unauthenticated clients to establish connections. Remote attackers can hold idle pre-authenticated sockets open to consume connection resources and degrade service availability for legitimate streams.

Affected products

openclaw
  • <2026.2.22
  • ==2026.2.22
voice-call
  • ==2026.2.22
  • ==2026.2.21

Matching in nixpkgs

Package maintainers