Executive brief
OpenClaw is an AI agent platform that processes webhook requests from various services including Zalo. An unauthenticated attacker can send requests with varying query parameters to a Zalo webhook endpoint, causing the application to accumulate unlimited memory and potentially crash the service, disrupting availability for all users.
Technical details
The vulnerability is an uncontrolled resource consumption issue (CWE-400) in the Zalo webhook security tracking mechanism. The vulnerable code fails to normalize query-string keys before storing webhook security state, allowing attackers to create unbounded in-memory key growth by sending unauthenticated requests with variant query parameters to the same webhook endpoint. No authentication is required and the attack is trivial to execute. A successful attack causes memory exhaustion, process instability, and out-of-memory errors. The fix normalizes keys to matched webhook path semantics (excluding query strings) and bounds/prunes tracking state.
Affected products
- OpenClaw OpenClaw <= 2026.2.26
CVE identifiers
- CVE-2026-32066
- CVE-2026-28461
Timeline
- 2026-03-02: disclosed: Advisory GHSA-wr6m-jg37-68xh published
- 2026-03-01: patched: Patch version 2026.3.1 released