OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to exhaust server resources without authentication by bypassing signature validation.
References
Configurations
History
15 Apr 2026, 17:22
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openclaw openclaw
Openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 - Patch | |
| References | () https://github.com/openclaw/openclaw/commit/651dc7450b68a5396a009db78ef9382633707ead - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-rm59-992w-x2mv - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-unauthenticated-resource-exhaustion-via-voice-call-webhook - Third Party Advisory |
09 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-09 22:16
Updated : 2026-04-15 17:22
NVD link : CVE-2026-35626
Mitre link : CVE-2026-35626
CVE.ORG link : CVE-2026-35626
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-405
Asymmetric Resource Consumption (Amplification)
