OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers to cause transient availability loss. Remote attackers can flood the webhook endpoint with concurrent requests before signature verification to exhaust resources and degrade service availability.
References
Configurations
History
28 Apr 2026, 18:56
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw openclaw
Openclaw |
|
| References | () https://github.com/openclaw/openclaw/commit/57c47d8c7fbf5a2e70cc4dec2380977968903cad - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-qcc3-jqwp-5vh2 - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-denial-of-service-via-line-webhook-handler-pre-auth-concurrency - Third Party Advisory |
23 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-23 22:16
Updated : 2026-04-28 18:56
NVD link : CVE-2026-41343
Mitre link : CVE-2026-41343
CVE.ORG link : CVE-2026-41343
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-799
Improper Control of Interaction Frequency
