Junglewise Threat Intelligence

CVE-2026-32980: OpenClaw Telegram webhook resource exhaustion via unauthenticated request body reading

CVE-2026-32980 · Severity: low · CVSS 3.1 · Published 2026-03-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Node.js library that handles Telegram bot webhook requests. A flaw in versions up to 2026.3.12 reads and processes incoming request bodies before validating authentication credentials, allowing unauthenticated attackers to force the server to consume memory and CPU on bogus requests, potentially degrading service availability.

Technical details

The vulnerability is an authentication-order flaw (CWE-400, CWE-770) in the Telegram webhook listener (src/telegram/webhook.ts). The vulnerable code path calls readJsonBodyWithLimit(...) to buffer and parse the HTTP request body before checking the x-telegram-bot-api-secret-token header. An unauthenticated network attacker can exploit this by sending large or malformed POST requests to the webhook endpoint, forcing the server to allocate memory and perform JSON parsing work before the request is rejected with a 401 response. The fix (version 2026.3.13) performs secret header validation before any body I/O, immediately rejecting unauthenticated requests with minimal resource consumption.

Affected products

  • OpenClaw openclaw <= 2026.3.12

Timeline

  • 2026-03-16: disclosed
  • 2026-03-16: patched: Fixed in version 2026.3.13

References

Related threats