Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-94094— OpenClaw Canvas Host Route server.ts createCanvasHostHandler denial of service

Quick assessment

Affected
n/a OpenClaw
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 OpenClaw 2026.9.5 及之前版本中发现了一个漏洞。该漏洞影响了 Canvas Host Route 组件中文件 的 函数。攻击者可通过远程执行特定操作导致拒绝服务(DoS)。该漏洞的利用代码已公开,可能被用于实际攻击。 修复建议中提到的 “streaming/size-limit”(流式处理/大小限制)功能并未实际发布——最新版本的 2026.9.5 仍通过 函数缓冲整个文件(参见 第 17 行和第 114 行),而与其并列的 WebSocket 路径则已将数据大小限制在 64KB。漏洞披露方已在

CVSS 4.3 · Medium

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94094

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenClaw Canvas Host Route server.ts createCanvasHostHandler denial of service
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. Fix suggestion's "streaming/size-limit" was never shipped - latest 2026.9.5 still buffers the whole file via readFile() (src/canvas/serve.runtime.ts:17,114), unlike the sibling WS path which caps at 64KB. The vendor was contacted early about this disclosure.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
不恰当的资源关闭或释放
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- OpenClaw 2026.9.0 cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-94094

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94094

登录查看更多情报信息。

Exploits & Public PoCs for CVE-2026-94094 (1)

Same Patch Batch · n/a · 2026-09-20 · 6 CVEs total

CVE-2026-93962 8.3 HIGH Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow
CVE-2026-94004 7.3 HIGH DedeCMS mytag_js.php code injection
CVE-2026-94043 5.3 MEDIUM Free5GC Gmm handler.go race condition
CVE-2026-93960 4.3 MEDIUM Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication
CVE-2026-94030 3.1 LOW SerenityOS LibGfx BMPLoader.cpp decode_bmp_pixel_data integer overflow

IV. Related Vulnerabilities

V. Comments for CVE-2026-94094

No comments yet


Leave a comment