Junglewise Threat Intelligence

CVE-2026-34505: OpenClaw rate limiting bypass in Zalo webhook handler

CVE-2026-34505 · Severity: medium · CVSS 6.5 · Published 2026-03-31

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a platform that processes webhook events from Zalo, a messaging service. The Zalo webhook handler only enforced rate limiting after validating the webhook secret, allowing attackers to repeatedly guess weak secrets without triggering rate-limit blocks. Once guessed, attackers could inject forged webhook messages into the platform.

Technical details

The vulnerability is an improper restriction of excessive authentication attempts (CWE-307). The Zalo webhook handler applied rate limiting only after successful secret validation, so invalid-secret requests returned 401 and did not consume rate-limiter budget. This allowed an attacker to brute-force the webhook secret by sending repeated requests with different secret guesses without triggering 429 Too Many Requests responses. The attack requires network access to the webhook endpoint and no authentication. Once the secret is guessed, an attacker can forge Zalo webhook traffic. The fix, released in openclaw 2026.3.12, applies rate limiting before authentication, ensuring that both valid and invalid secret guesses consume the same rate-limit budget.

Affected products

  • openclaw openclaw <= 2026.3.11

Timeline

  • 2026-03-13: disclosed: Advisory published
  • 2026-03-12: patched: Fix released in openclaw 2026.3.12

References

Related threats