Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 20 Sep 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. Fix suggestion's "streaming/size-limit" was never shipped - latest 2026.9.5 still buffers the whole file via readFile() (src/canvas/serve.runtime.ts:17,114), unlike the sibling WS path which caps at 64KB. The vendor was contacted early about this disclosure. | |
| Title | OpenClaw Canvas Host Route server.ts createCanvasHostHandler denial of service | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-404 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-20T23:00:14.987Z
Reserved: 2026-09-20T09:07:39.802Z
Link: CVE-2026-94094
No data.
Status : Received
Published: 2026-09-20T23:17:03.530
Modified: 2026-09-20T23:17:03.530
Link: CVE-2026-94094
No data.
OpenCVE Enrichment
Updated: 2026-09-21T01:00:08Z
-
CWE-404
Improper Resource Shutdown or Release