CVE-2026-62220: OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce service availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.26 - Configuration
Disable the affected WebSocket authentication feature or restrict its reachability so lower-trust callers/configured input paths cannot bypass the non-browser rate limits.
OpenClaw WebSocket authentication feature non-browser rate limits bypass exposure (affected feature enabled and reachable by lower-trust input) = disable or restrict reachability
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62220?
CVE-2026-62220 has a medium severity rating of 6.3.
How do I fix CVE-2026-62220?
To fix CVE-2026-62220, upgrade OpenClaw to version 2026.5.26 or later.
What type of attack does CVE-2026-62220 enable?
CVE-2026-62220 enables a rate limit bypass on WebSocket authentication attempts.
What are the potential impacts of CVE-2026-62220?
The potential impacts of CVE-2026-62220 include resource consumption and reduced service availability.
Which version of OpenClaw is affected by CVE-2026-62220?
OpenClaw versions prior to 2026.5.26 are affected by CVE-2026-62220.