Executive brief
OpenClaw is a webhook management service that integrates with messaging platforms like BlueBubbles and Google Chat. A vulnerability allows unauthenticated attackers to send slow or oversized request bodies to webhook endpoints, causing the server to waste computational resources and become unavailable to legitimate users. An attacker can repeatedly exploit this flaw to degrade service availability without needing to authenticate.
Technical details
OpenClaw's webhook handlers for BlueBubbles and Google Chat parse request bodies before performing authentication and signature verification. This pre-auth body parsing can be exploited via uncontrolled resource consumption (CWE-400, CWE-770): an attacker sends slow-read or oversized HTTP request bodies to hold parser work open, exhausting server resources. The vulnerability affects releases up to 2026.3.1 and requires no authentication or special preconditions—any network-reachable client can trigger it. The attack surface includes unauthenticated HTTP POST requests to affected webhook paths. A patch (version 2026.3.2) enforces authentication before body parsing, implements strict pre-auth body and time budgets, and introduces request-level guardrails.
Affected products
- OpenClaw OpenClaw <= 2026.3.1
Timeline
- 2026-03-03: disclosed: GHSA-x4vp-4235-65hg published
- 2026-03-03: patched: Version 2026.3.2 released with fix
- 2026-03-19: other: NVD entry published for CVE-2026-32011