Junglewise Threat Intelligence

CVE-2026-35640: OpenClaw uncontrolled resource consumption in Feishu webhook

CVE-2026-35640 · Severity: medium · CVSS 4 · Published 2026-03-29

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI automation platform that integrates with Feishu (a workplace collaboration tool) via webhooks. The vulnerability allows unauthenticated attackers to send malicious webhook requests that trigger resource-intensive JSON parsing operations before the application validates the request signature. An attacker can exploit this to exhaust server resources and cause service unavailability.

Technical details

The vulnerability stems from the order of operations in Feishu webhook handling: OpenClaw was parsing JSON request bodies before performing signature validation. The root cause is a classic CWE-400 (Uncontrolled Resource Consumption) combined with improper input validation ordering. An unauthenticated network attacker can send crafted webhook requests with large or complex JSON payloads to any exposed Feishu webhook endpoint without authentication or user interaction. The server performs full JSON parsing before rejecting the request due to invalid signature, consuming CPU and memory resources. The fix (commit 5e8cb22) changes the code to read and validate the raw request body signature first, then parse JSON only for authenticated requests. Affected versions are up to 2026.3.24; patched version is 2026.3.25 or later.

Affected products

  • OpenClaw openclaw <=2026.3.24

Timeline

  • 2026-03-29: disclosed: Security advisory published
  • 2026-03-26: patched: Fix commit 5e8cb22 merged; patched version 2026.3.25 planned

References

Related threats