Junglewise Threat Intelligence

CVE-2026-32066: OpenClaw unbounded memory growth in Zalo webhook via query-string key churn

CVE-2026-32066 · Severity: medium · CVSS 4 · Published 2026-03-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI agent platform that processes webhook requests from various services including Zalo. An unauthenticated attacker can send requests with varying query parameters to a Zalo webhook endpoint, causing the application to accumulate unlimited memory and potentially crash the service, disrupting availability for all users.

Technical details

The vulnerability is an uncontrolled resource consumption issue (CWE-400) in the Zalo webhook security tracking mechanism. The vulnerable code fails to normalize query-string keys before storing webhook security state, allowing attackers to create unbounded in-memory key growth by sending unauthenticated requests with variant query parameters to the same webhook endpoint. No authentication is required and the attack is trivial to execute. A successful attack causes memory exhaustion, process instability, and out-of-memory errors. The fix normalizes keys to matched webhook path semantics (excluding query strings) and bounds/prunes tracking state.

Affected products

  • OpenClaw OpenClaw <= 2026.2.26

CVE identifiers

  • CVE-2026-32066
  • CVE-2026-28461

Timeline

  • 2026-03-02: disclosed: Advisory GHSA-wr6m-jg37-68xh published
  • 2026-03-01: patched: Patch version 2026.3.1 released

References

Related threats