Junglewise Threat Intelligence

CVE-2026-41405: OpenClaw MS Teams webhook unauthenticated resource exhaustion

CVE-2026-41405 · Severity: low · CVSS 3.1 · Published 2026-04-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Node.js library that handles Microsoft Teams webhook integrations. The library parses incoming webhook request bodies before validating the JWT authentication token, allowing attackers to send malformed or excessively large payloads without authentication. This can exhaust server resources (memory, CPU) and cause service degradation or outages.

Technical details

The vulnerability is a resource exhaustion issue (CWE-400, CWE-408) in OpenClaw's MS Teams webhook handler. The application performs JSON body parsing immediately after checking for a Bearer token prefix, but before validating the JWT signature. An unauthenticated attacker can send the library a network request with a malicious "Authorization: Bearer" header and a large or maliciously crafted JSON body, triggering resource-intensive parsing operations without authentication checks. This allows denial-of-service attacks. The fix was released in version 2026.3.31, which implements proper JWT validation before parsing the request body.

Affected products

  • OpenClaw openclaw <=2026.3.28

Timeline

  • 2026-04-03: disclosed
  • 2026-03-30: patched: Fix commit 3834d47099dd13c8244ed6de8b9ea9855c553623
  • 2026-03-31: other: Patched version 2026.3.31 released

References

Related threats