Summary
Incomplete fix for CVE-2026-32062: voice-call still parses large WebSocket frames before start validation
Current Maintainer Triage
- Normalized severity: medium
- Assessment: v2026.3.28 still parses oversized pre-start voice-call WebSocket frames before start validation, and the unreleased maxPayload fix confirms the shipped resource-consumption bug remains open.
Affected Packages / Versions
- Package:
openclaw (npm)
- Latest published npm version:
2026.3.31
- Vulnerable version range:
<=2026.3.28
- Patched versions:
>= 2026.3.31
- First stable tag containing the fix:
v2026.3.31
Fix Commit(s)
9abcfdadf591bf266d85fbdfe14ae833e557a110 — 2026-03-31T19:47:10+09:00
OpenClaw thanks @Kazamayc for reporting.
References
Summary
Incomplete fix for CVE-2026-32062: voice-call still parses large WebSocket frames before start validation
Current Maintainer Triage
Affected Packages / Versions
openclaw(npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.31Fix Commit(s)
9abcfdadf591bf266d85fbdfe14ae833e557a110— 2026-03-31T19:47:10+09:00OpenClaw thanks @Kazamayc for reporting.
References