Executive brief
OpenClaw is a Node.js library that handles Telegram bot webhook requests. A flaw in versions up to 2026.3.12 reads and processes incoming request bodies before validating authentication credentials, allowing unauthenticated attackers to force the server to consume memory and CPU on bogus requests, potentially degrading service availability.
Technical details
The vulnerability is an authentication-order flaw (CWE-400, CWE-770) in the Telegram webhook listener (src/telegram/webhook.ts). The vulnerable code path calls readJsonBodyWithLimit(...) to buffer and parse the HTTP request body before checking the x-telegram-bot-api-secret-token header. An unauthenticated network attacker can exploit this by sending large or malformed POST requests to the webhook endpoint, forcing the server to allocate memory and perform JSON parsing work before the request is rejected with a 401 response. The fix (version 2026.3.13) performs secret header validation before any body I/O, immediately rejecting unauthenticated requests with minimal resource consumption.
Affected products
- OpenClaw openclaw <= 2026.3.12
Timeline
- 2026-03-16: disclosed
- 2026-03-16: patched: Fixed in version 2026.3.13