OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because invalid webhook tokens are rejected without throttling repeated authentication attempts, enabling attackers to guess weak tokens through rapid successive requests.
References
Configurations
History
15 Apr 2026, 18:52
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openclaw openclaw
Openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/openclaw/openclaw/commit/0b4d07337467f4d40a0cc1ced83d45ceaec0863c - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-mf5g-6r6f-ghhm - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-pre-authentication-rate-limit-bypass-in-webhook-token-validation - Third Party Advisory |
09 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-09 22:16
Updated : 2026-04-15 18:52
NVD link : CVE-2026-35646
Mitre link : CVE-2026-35646
CVE.ORG link : CVE-2026-35646
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
