Executive brief
OpenClaw is an authentication library that manages user pairing and account access. The pairing request limit was incorrectly enforced across all accounts in a shared channel rather than per individual account, allowing one user's pending requests to block another user's legitimate pairing attempts. This could temporarily prevent new users from successfully onboarding or existing users from re-pairing their accounts until the backlog cleared.
Technical details
OpenClaw incorrectly enforced pending pairing-request rate limits at the channel level rather than per account. The vulnerability allows an attacker (or any user) to generate multiple pairing requests in a shared multi-account channel setup that collectively exceed the per-channel cap, which should have been scoped per account. This causes requests from other legitimate accounts to be dropped, resulting in denial-of-service for pairing and onboarding flows. The vulnerability requires network access to the OpenClaw service and no authentication bypass or data exfiltration is possible—the impact is purely availability. The fix (commit 9bc1f896c8cd325dd4761681e9bdb8c425f69785, released in version 2026.3.31 on March 31, 2026) properly scopes the pending-request caps per account.
Affected products
- OpenClaw openclaw >= 2026.2.26, < 2026.3.31
Timeline
- 2026-04-07: disclosed
- 2026-03-31: patched